Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » RedDelta Deploys PlugX Malware for Spy Campaigns Against Mongolia and Taiwan
Global Security

RedDelta Deploys PlugX Malware for Spy Campaigns Against Mongolia and Taiwan

AdminBy AdminJanuary 10, 2025No Comments3 Mins Read
PlugX Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 10, 2025Ravi LakshmananCyber ​​espionage / Cyber ​​attack

PlugX malware

Mongolia, Taiwan, Myanmar, Vietnam and Cambodia have been targeted by China-linked RedDelta threat to deliver a customized version of the PlugX backdoor between July 2023. until December 2024.

“The group used eye-catching documents on Taiwan’s 2024 presidential candidate Terry Gou, Vietnam’s national holidays, flood protection in Mongolia and invitations to meetings, including the Association of Southeast Asian Nations (ASEAN) meeting,” Insikt Group Recorded Future said in a new analysis.

The threat actor is believed to have compromised the Ministry of Defense of Mongolia in August 2024. and the Communist Party of Vietnam in November 2024. It is also alleged to have targeted various victims in Malaysia, Japan, the US, Ethiopia, Brazil, Australia and India between September and December 2024.

Cyber ​​security

RedDelta, which has been operating since at least 2012, is a pseudonym assigned to a state-based threat actor from China. The cybersecurity community also tracks it under the names BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, Mustang Panda (and its closely related Dizzy panda), Red Lich, Stately Taurus, TA416 and Twill Typhoon.

The hacking team is known for constantly improving the infection chain recent attacks weaponization of Visual Studio Code tunnels as part of espionage operations targeting government entities in Southeast Asia, a tactic increasingly used by various China-linked espionage groups such as Operation Digital Eye. and MirrorFace.

The intrusion kit documented by Recorded Future involves the use of the Windows Shortcut (LNK), the Windows Installer (MSI), and the Microsoft Management Console (MSC) files that are likely distributed via phishing as a first-stage component that starts the chain of infection that eventually leads to deployment PlugX using DLL sideloading methods.

Separate campaigns organized late last year also relied on phishing emails containing a link to HTML files hosted on Microsoft Azure as a starting point to trigger the download of the MSC payload, which in turn disables the MSI installer. responsible for loading PlugX with a legitimate executable vulnerable to DLL search order hacking.

Another sign of evolving its tactics and staying ahead of its defenses was RedDelta’s use of Cloudflare’s Content Delivery Network (CDN) to proxy command and control (C2) traffic to attacker-controlled C2 servers. This is done to blend in with legitimate CDN traffic and make detection more difficult.

Recorded Future said it identified 10 administrative servers that interacted with the two known RedDelta C2 servers. All 10 IP addresses are registered with China Unicom of Henan Province.

Cyber ​​security

“RedDelta’s operations are in line with China’s strategic priorities, focusing on governments and diplomatic organizations in Southeast Asia, Mongolia and Europe,” the company said.

“The group’s targeting of Asia in 2023 and 2024 represents a return to the group’s historical focus following its 2022 attack on European entities. RedDelta’s targeting of Mongolia and Taiwan coincides with the group’s past targeting of groups seen as a threat to Chinese Communist Party rule. .”

Development takes place against the background of a the report from Bloomberg that recent cyber attack The attack on the US Treasury Department was carried out by a hacking group known as Silk Typhoon (aka Hafnius), which was previously attributed zero day operation of four security flaws in Microsoft Exchange Server (aka ProxyLogon) in early 2021.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.