- NCSC Warns UK Shoppers Lost £11.5m Last Christmas
- The hidden challenges of AI development no one talks about
- Sólo el 21% de las empresas se apoya en la tecnología para diseñar estrategias de sostenibilidad
- How to upgrade an 'incompatible' Windows 10 PC to Windows 11: Two ways
- 우리 회사에 꼭 필요할까?!··· 전임 CISO가 있어야 할 9가지 상황
Chinese APT Group Returns to Target Catholic Church & Diplomatic Groups
Chinese advanced persistent threat (APT) group TA416, whose previous activity has been attributed to “Mustang Panda” and “RedDelta,” has resumed attack activity following a brief hiatus, Proofpoint researchers report.
This recent wave of activity appears to be a continuation of previously reported campaigns that have targeted organizations linked to diplomatic relations between the Vatican and the Chinese Communist Party, as well as entities in Myanmar and groups conducting diplomacy in Africa.
The most recent period of activity spanned Sept. 16 through Oct. 10, 2020, a time that included a Chinese national holiday known as National Day and subsequent unofficial vacation period known as Golden Week. Attackers leveraged social engineering lures that referenced an agreement recently renewed between the Vatican Holy See and Chinese Communist Party. Researchers also detected spoofed email headers designed to appear as though they came from journalists reporting from the Union of Catholic Asia News.
Researchers have spotted updates to the actor’s tool set, which they say is used to deliver PlugX malware payloads. More specifically, they detected a new Golang variant of TA416’s PlugX malware loader and noticed the PlugX malware is consistently used in targeted campaigns. This signifies the group’s persistence in changing its tool set to evade detection, researchers say.
“While baseline changes to their payloads do not greatly increase the difficulty of attributing TA416 campaigns, they do make automated detection and execution of malware components independent from the infection chain more challenging for researchers,” they write.
Read the full Proofpoint blog post for more details.
Dark Reading’s Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
Recommended Reading:
More Insights