Topic
China
8 reports tagged China, spanning campaign, threat actor and malware coverage.
Articles tagged China
-
CampaignAPT41 DUST
APT41's use of DUSTPAN and the newly observed DUSTTRAP malware, alongside Cobalt Strike and certutil, against shipping, logistics, and media entities in Europe, Asia, and the Middle East from 2023 to mid-2024.
-
CampaignCutting Edge
Campaign by suspected China-nexus espionage actors exploiting zero-day vulnerabilities in Ivanti Connect Secure VPN appliances beginning December 2023, targeting the US defense industrial base and multiple global sectors.
-
Threat ActorVolt Typhoon
PRC state-sponsored actor, per MITRE ATT&CK, active since at least 2021, pre-positioning within US critical infrastructure using living-off-the-land techniques rather than custom malware.
-
Threat ActorMustang Panda
China-based cyber espionage actor, per MITRE ATT&CK, conducting operations since at least 2012 using tailored phishing lures against government, diplomatic, and NGO targets.
-
CampaignOperation Wocao
Cyber espionage campaign by suspected China-based actors, per MITRE ATT&CK, that compromised government organizations, managed service providers, and multiple industries across ten countries from late 2017 to late 2019.
-
MalwarePlugX
Modular remote access tool with plugin architecture, per MITRE ATT&CK, used by multiple China-linked threat groups and the subject of a December 2024 US DOJ court-authorized disruption operation.
-
CampaignNight Dragon
Cyber espionage campaign targeting oil, energy, and petrochemical companies and executives in Kazakhstan, Taiwan, Greece, and the United States, collecting SCADA and production data, assessed as China-based.
-
Threat ActorAPT41
Chinese state-sponsored espionage group, per MITRE ATT&CK, that also conducts financially motivated operations, active since at least 2012 across 14 countries and multiple industries.