Menu

Post image 1
Post image 2
Post image 3
Post image 4
1 / 4
0

What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia

go.theregister.com·Jessica Lyons·about 1 month ago
#UIJ8QqCQ
#shadow#earth#typhoon#group#chinese#article
Reading 0:00
15s threshold

Exclusive A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in December 2024 and with activity uncovered as recently as this month. I'm concerned about what they are leaving behind: What type of C2 on a sleep cycle is still lingering in these environments? In a report shared exclusively with The Register , TrendAI researchers say the new group, which they track as Shadow-Earth-053, targeted government agencies, defense contractors, technology firms, and the transportation industry. The Chinese spies typically gain initial access to victim environments via vulnerable Microsoft Exchange Servers.  In "multiple" of these intrusions, they compromised victim organizations up to 8 months before deploying ShadowPad , a custom backdoor used by China's APT41 for almost a decade, and shared among multiple China-aligned groups since 2019.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More