logo

Beyond the Watering Hole: APT24's Pivot to Multi-Vector Attacks

ID: cce360c6-6134-5d03-8696-8d6d60708b4d

STIX ID: report--cce360c6-6134-5d03-8696-8d6d60708b4d

Feed Name: Threat Intelligence

Threat Score
85/100

Date Published: 2025-11-20

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

APT24, a PRC-nexus actor, executed a nearly three-year targeted phishing and web compromise campaign leveraging supply-chain techniques, multi-layered social engineering, pixel tracking, and abuse of legitimate cloud storage (Google Drive/OneDrive) to distribute BADAUDIO malware; Google GTIG and partners observed and mitigated activity and published related IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.