Chinese APT Group Returns to Target Catholic Church & Diplomatic Groups

  /     /     /  
Publicated : 23/11/2024   Category : security


Chinese APT Group Returns to Target Catholic Church & Diplomatic Groups


APT group TA416 reemerges with new changes to its documented tool sets so it can continue launching espionage campaigns.



Chinese advanced persistent threat (APT) group TA416, whose previous activity has been attributed to Mustang Panda and RedDelta, has resumed attack activity following a brief hiatus, Proofpoint researchers report. 
This recent wave of activity appears to be a continuation of previously reported campaigns that have targeted organizations linked to diplomatic relations between the Vatican and the Chinese Communist Party, as well as entities in Myanmar and groups conducting diplomacy in Africa.
The most recent period of activity spanned Sept. 16 through Oct. 10, 2020, a time that included a Chinese national holiday known as National Day and subsequent unofficial vacation period known as Golden Week. Attackers leveraged social engineering lures that referenced an agreement recently renewed between the Vatican Holy See and Chinese Communist Party. Researchers also detected spoofed email headers designed to appear as though they came from journalists reporting from the Union of Catholic Asia News.
Researchers have spotted updates to the actors tool set, which they say is used to deliver PlugX malware payloads. More specifically, they detected a new Golang variant of TA416s PlugX malware loader and noticed the PlugX malware is consistently used in targeted campaigns. This signifies the groups persistence in changing its tool set to evade detection, researchers say.
While baseline changes to their payloads do not greatly increase the difficulty of attributing TA416 campaigns, they do make automated detection and execution of malware components independent from the infection chain more challenging for researchers, they write.
Read the full
Proofpoint blog post
for more details.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Chinese APT Group Returns to Target Catholic Church & Diplomatic Groups