Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Anthropic MCP Critical Vulnerability Exposes Developer Machines to Remote Exploits

TA829 and UNK_GREENSEC share tactics and infrastructure in an ongoing malware campaign

Note: Raising $16 million to build a human-driven expert model for e-commerce

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » 10 Month Campaign, 7 Global Targets, 5 Malware Families
Identity

10 Month Campaign, 7 Global Targets, 5 Malware Families

userBy userMarch 21, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 21, 2025Ravi LakshmananCybercrime / Cyberspy

China linked apt

China-related Advanced Persistent Threat (APT) Group. Known as Aquatic Panda, it is linked to the 2022 “Global Spy Campaign” targeting seven organizations.

These entities include government, Catholic charities, non-governmental organizations (NGOs), and think tanks from Taiwan, Hungary, Turkey, Thailand, France, and the United States. The activity that took place over 10 months between January and October 2022 has been called Operation Fishmedley by ESET.

“Operators used general or exclusive Shadowpad, Sodamaster, Spyder and other implants that were placed in China,” security researcher Matthieu Faou said in the analysis.

Cybersecurity

Also known as Bronze University, Charcoal Wind, Earthluska, and Red Hotel, Aquatic Panda is a Chinese cyberspy group known to have been active since at least 2019. A Slovak cybersecurity company is tracking a hacking crew under the name Fishmonger.

As it is said to be operating under Winnti Group Umbrella (aka APT41, Barium, or Bronze Atlas), the threat actor is overseen by Chinese contractor I-SOON.

The hostile group also traces a retrospective look at a campaign in late 2019 that targeted Hong Kong universities using Shadowpad and Winnti malware.

The 2022 attack is characterized by the use of five different malware families. A loader named ScatterBee used to drop shadow pads, Spyder, Sodamaster, and RpipeCommander. The exact initial access vector used in the campaign is unknown at this stage.

Cybersecurity

“APT10 was the first group known to have access to. [SodaMaster] However, Operation Fish Medley shows that it could now be shared among multiple APT groups lined up in China,” ESET said.

Rpipecommander is the name given to a previously undocumented C++ implant that was deployed against unspecified government organizations in Thailand. It acts as a reverse shell that allows you to run commands using CMD.exe and collect output.

“This group is not shy about reusing well-known implants such as Shadowpad and Sodamaster.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWhere does the increase in carbon sequestration come from?
Next Article Israel is threatening with annexation after ground invasion in northern South Gaza | News
user
  • Website

Related Posts

Anthropic MCP Critical Vulnerability Exposes Developer Machines to Remote Exploits

July 1, 2025

TA829 and UNK_GREENSEC share tactics and infrastructure in an ongoing malware campaign

July 1, 2025

New flaws in IDES like Visual Studio code allow malicious extensions to bypass validated status

July 1, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Anthropic MCP Critical Vulnerability Exposes Developer Machines to Remote Exploits

TA829 and UNK_GREENSEC share tactics and infrastructure in an ongoing malware campaign

Note: Raising $16 million to build a human-driven expert model for e-commerce

When the app moves further away from Instagram, the thread launches its own DM inbox

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

TwinH: Digital Human Twin Aims for Victory at Break the Gap 2025

The Digital Twin Revolution: Reshaping Industry 4.0

1-inch rollout expanded bug bounty features rewards up to $500,000

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.