Minacce e avversari · Spionaggio APT
Unit 42 ha rilevato tre cluster di attività allineati alla Cina che prendevano di mira un governo del sud-est asiatico nel 2025. I cluster hanno operato in periodi sovrapposti e hanno distribuito più catene di strumenti malware distinte per creare accesso ridondante a lungo termine. Mustang Panda ha usato un loader HIUPAN basato su USB per veicolare il backdoor PUBLOAD e ha mantenuto un impianto COOLCLIENT di lunga durata. Altri cluster (CL-STA-1048 e CL-STA-1049) hanno usato backdoor e loader diversi, complicando il rilevamento e la mitigazione.
1 fonte · 30 mar
The Hacker News
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
Three China-linked clusters targeted a Southeast Asian government in 2025, deploying multiple malware families to secure persistent access.
originalePart of the PlainSec briefing for 2026-03-31
Every edition of this story: Cluster allineati alla Cina hanno costruito persistenza ridondante in una rete governativa