216.73.217.22

APT32 Poisoning GitHub, Targeting Chinese Cybersecurity Professionals and Specific Large Enterprises

· Published 09/01/2025 08:56 · Modified 09/01/2025 09:38

Export JSON

Essential information

Published
09/01/2025 08:56
Modified
09/01/2025 09:38
Tags
2025-01-09 cobalt strike dll hollowing notion api oceanlotus
Related entities
1 intrusion sets (apt), 17 techniques (mitre), 1 malware, 2 others

Description

APT32 () has launched a sophisticated attack targeting Chinese cybersecurity professionals and specific large enterprises. The group released a exploit plugin with a Trojan on GitHub, embedding a malicious .suo file into a Visual Studio project. When compiled, the Trojan executes automatically. The attack, occurring between mid-September and early October 2024, used GitHub poisoning as the primary vector. The attackers disguised themselves as a security researcher from a leading Chinese FinTech company, publishing malicious projects with Chinese descriptions. The technique involved calling the .suo file, which executes once and then self-deletes, making detection challenging. The malware uses and communicates via the to evade detection.

External references