Tech

China government-linked hackers caught running a seriously dangerous ransomware scam

Share
Share


  • Symantec researchers observed Chinese state-sponsored threat actors running ransomware against an Asian software and services firm
  • They claim it’s highly unusual activity for state attackers
  • The attackers demanded $2 million in ransom

Emperor Dragonfly, a known Chinese state-sponsored threat actor, recently did something unusual – it deployed a ransomware encryptor on a target’s network.

A report from Symantec’s Threat Hunter Team, which observed the attack in late 2024, noted how they had observed, on multiple occasions, the group doing what it usually does – side-loading malicious DLL files (via a legitimate Toshiba executable) to drop backdoors and establish persistence. The goal was, as it’s usual with state-sponsored attackers, cyber-espionage.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up
Tech

5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up

There’s nothing quite like the excitement of a new console; feverishly whipping...

Websites are tracking you via browser fingerprinting, researchers show
Tech

Websites are tracking you via browser fingerprinting, researchers show

Credit: Pixabay/CC0 Public Domain Clearing your cookies is not enough to protect...

Psycholinguist talks nonsense to ChatGPT to understand how it processes language
Tech

Psycholinguist talks nonsense to ChatGPT to understand how it processes language

Credit: Pixabay/CC0 Public Domain A new study appearing in PLOS One by...