Tech

China government-linked hackers caught running a seriously dangerous ransomware scam

Share
Share


  • Symantec researchers observed Chinese state-sponsored threat actors running ransomware against an Asian software and services firm
  • They claim it’s highly unusual activity for state attackers
  • The attackers demanded $2 million in ransom

Emperor Dragonfly, a known Chinese state-sponsored threat actor, recently did something unusual – it deployed a ransomware encryptor on a target’s network.

A report from Symantec’s Threat Hunter Team, which observed the attack in late 2024, noted how they had observed, on multiple occasions, the group doing what it usually does – side-loading malicious DLL files (via a legitimate Toshiba executable) to drop backdoors and establish persistence. The goal was, as it’s usual with state-sponsored attackers, cyber-espionage.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Some AI prompts could cause 50 times more CO₂ emissions than others, researchers find
Tech

Some AI prompts could cause 50 times more CO₂ emissions than others, researchers find

Credit: Sanket Mishra from Pexels No matter which questions we ask an...

Google Gemini’s super-fast Flash-Lite 2.5 model is out now – here’s why you should switch today
Tech

Google Gemini’s super-fast Flash-Lite 2.5 model is out now – here’s why you should switch today

Google’s new Gemini 2.5 Flash-Lite model is its fastest and most cost-efficient...

5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up
Tech

5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up

There’s nothing quite like the excitement of a new console; feverishly whipping...