Blog
Share This Post
[ad_1]

More extensive compromise of Southeast Asian government organizations have been conducted by three China-linked threat clusters as part of the state-sponsored Crimson Palace cyberespionage operation, The Hacker News reports.
Simultaneous target infiltration and reconnaissance, network compromise, and data exfiltration activities have been performed by Clusters Alpha, Bravo, and Charlie, respectively, beginning March 2023, according to an analysis from Sophos. Despite only being active last March, the Unfading Sea Haze-linked Cluster Bravo was observed to have targeted nearly a dozen government agencies and organizations across Southeast Asia between January and June, while the Earth Longzhi-linked Cluster Charlie was able to deliver various command-and-control frameworks and malicious payloads from September 2023 to June 2024. Attacks by Cluster Charlie also involved open-source programs Alcatraz and RealBlindingEDR for antivirus systems bypass, as well as the TattleTale keylogger. “Throughout the engagement, the adversary appeared to continually test and refine their techniques, tools, and practices,” researchers said.
[ad_2]
Source link
Subscribe To Our Newsletter
Get updates and learn from the best
More To Explore
US Charges Five People Over North Korean IT Worker Scheme
[ad_1] The US has announced charges against five individuals involved in a fake IT workers scheme to funnel funds to
In Other News: VPN Supply Chain Attack, PayPal $2M Settlement, RAT Builder Hacks Script Kiddies
[ad_1] Noteworthy stories that might have slipped under the radar: Korean VPN supply chain attack, PayPal settles with New York