216.73.217.80

Analysis of Recent Attack Activities Targeting China Using Research Project Plans as Bait

· Published 10/12/2024 14:59 · Modified 10/12/2024 15:33

Export JSON

Essential information

Published
10/12/2024 14:59
Modified
10/12/2024 15:33
Tags
2024-12-10 asyncrat badnews
Related entities
1 intrusion sets (apt), 16 techniques (mitre), 2 malware, 4 others

Description

The Patchwork APT group, also known as Hangover and Dropping Elephant, has been conducting cyber espionage activities since 2009, primarily targeting Asian countries including China and Pakistan. Recently, they launched a phishing campaign against Chinese research personnel using a document titled 'National Key R&D Program Engineering Science and Comprehensive Interdisciplinary Key Special 2025 Project Guide Suggestion Form' as bait. The attack uses LNK files as initial payload, downloads PDF and executable files, sets up scheduled tasks, and ultimately loads the malware. The group impersonates legitimate websites and employs various techniques to evade detection and gather sensitive information from targeted systems.

External references