Chinese APT Exploits New Malware to Prolong Network Access

A Chinese-linked espionage group, tracked as UNC5221 or VerdantBamboo, exploited new malware to secretly maintain access to US networks for over 18 months, evading detection by blending in with legitimate traffic. The attackers used a sophisticated backdoor called Brickstorm to prolong their stay undetected.

https://osintsights.com/chinese-apt-exploits-new-malware-to-prolong-network-access?utm_source=mastodon&utm_medium=social

#ChineseApt #MalwareOperations #NationState #Unc5221 #Verdantbamboo

Chinese APT Exploits New Malware to Prolong Network Access

Learn how Chinese APT group UNC5221 uses new malware to prolong network access and evade detection, and take steps to protect your organization now.

OSINTSights

🚨 RedNovember: A Chinese state-backed APT is scaling global cyber-espionage.

🔍 Victims: US defense contractors, European aerospace, ministries of foreign affairs

⚠️ Tactics: VPN & firewall exploitation + open-source backdoors (Pantegana, Cobalt Strike, SparkRAT)

🌍 Activity aligned with Taiwan drills & Panama Canal disputes

Edge devices remain the weakest link.
💬 What’s your take? Follow @technadu for more in-depth threat intel.

#Cybersecurity #RedNovember #APT #InfoSec #ThreatIntel #ChineseAPT #CyberDefense #CriticalInfrastructure

Chinese APT Debuts Sepulcher Malware in Spear-Phishing Attacks

The RAT has been distributed in various campaigns over the past six months, targeting both European officials and Tibetan dissidents.

Threatpost - English - Global - threatpost.com

#中国国内安全问题中的主要问题,以及可能是 #MSS的目标,已被非正式地称为
#五毒

这个名称是指五个群体,他们的意识形态,宗教或文化差异要么直接挑战执政党结构,要么使他们与政府单一的“一个中国”的民族认同概念不一致

Reaver: Mapping Connections Between Disparate #ChineseAPT Groups

https://threatvector.cylance.com/en_us/home/reaver-mapping-connections-between-disparate-chinese-apt-groups.html

Reaver: Mapping Connections Between Disparate Chinese APT Groups

New research links an attack featured in a front-page New York Times story about the theft of sensitive European Union diplomatic cables by an alleged Chinese APT to a whole host of additional attacks on internal Chinese political targets thought to have been carried out by different Chinese APT groups.