Security News > 2022 > April > Chinese state-backed hackers now target Russian state officers

Chinese state-backed hackers now target Russian state officers
2022-04-27 12:38

Security researchers analyzing a phishing campaign targeting Russian officials found evidence that points to the China-based threat actor tracked as Mustang Panda.

The threat group was previously seen orchestrating intelligence collection campaigns against European targets, employing phishing lures inspired by the Russian invasion of Ukraine.

Upon launching the executable, a host of additional files are fetched, including the previously mentioned decoy EU document, a malicious DLL loader, an encrypted PlugX variant, and a digitally signed.

Loading PlugX. The DLL loader performs DLL search order hijacking using a legitimate signed file that is vulnerable to this trick.

Dll DLL loader in a stealthy manner that does not trigger security solutions on the system.

Although Mustang Panda continues deploying the same malware strains and loader tools, and even though parts of its infrastructure overlap with past campaigns, the threat actor remains relatively stealthy and potent.


News URL

https://www.bleepingcomputer.com/news/security/chinese-state-backed-hackers-now-target-russian-state-officers/