A China-linked advanced threat group named Weaver Ant spent more than four years in the network of a telecommunications ...
Researchers spot Medusa ransomware operators deploying smuol.sys This driver mimics a legitimate CrowdStrike Falcon driver Medusa is actively targeting critical infrastructure organizations Operators ...
The Medusa ransomware relies on a malicious Windows driver to disable the security tools running on the infected systems.
The FishMonger APT group, a subdivision of Chinese cybersecurity firm I-Soon, compromised seven organizations in a 2022 ...
UNC3886 exploits Juniper routers with six TinyShell-based backdoors, evading detection and maintaining persistence.
The U.S. DOJ indicted a dozen Chinese nationals for their role in a years-long hacker-for-hire campaign that included the Chinese government using private companies and freelance hackers to steal data ...
Eight employees of a Chinese company called Anxun Information Technology ... conducted reconnaissance once inside those networks, and installed malware, such as PlugX malware, that provided persistent ...
Additionally, APT27 has been associated with the distribution of the PlugX malware, a tool used by alleged Chinese state-backed threat groups. The Justice Department’s actions include the ...
Vault Panda has used many malware families shared by Chinese threat actors ... Meanwhile Envoy Panda is known for its use of Turian, PlugX, and Smanager. PlugX, aka Korplug, is one of the oldest ...