Skip to main content

Tag: china linked apt

3 articles

Interconnected devices in a neutral setting, forming a network.

China-Linked APT Bolsters Proxy Network with Custom Malware Arsenal

Meet UAT-7810, a China-linked advanced persistent threat that's rapidly expanding its proxy network with custom malware, allowing other attackers to hide their tracks and route traffic through compromised devices. This sophisticated operation, known as LapDogs, has been providing infrastructure for malicious activities for years.

Analyst 207
Cramped network closet with rows of equipment, patch panels, and tangled cables.

China-Linked APT Expands ORB Network with LONGLEASH Malware

Meet UAT-7810, a Chinese threat actor with a mission to build and expand Operational Relay Box (ORB) networks, which can be hijacked by other malicious groups to launch targeted attacks on high-value targets. Their latest move involves deploying the LONGLEASH malware to supercharge their ORB network.

Analyst 207
Modern office setting with subtle digital communication hints.

China-Linked APT Group Exploits Legitimate Services for Covert Ops

ESET researchers have uncovered a treasure trove of clues, analyzing 6,044 Slack messages and 3,005 Discord messages that reveal the covert operations of a China-linked APT group, dubbed GopherWhisper, which has been active since at least 2023. The recovered logs provide a rare glimpse into the group's tactics, thanks to hardcoded credentials in Go-based backdoors that gave investigators access to the group's command and control channels.

Analyst 207