A sophisticated cyber espionage campaign linked to Chinese state-aligned threat actors has targeted organizations across 15 countries using an updated variant of the Shadowpad malware to deploy previously undocumented ransomware. Security analysts at Trend Micro identified that once inside, they leverage Shadowpad—a modular backdoor connected to multiple Chinese advanced persistent threat (APT) groups—to establish persistence, exfiltrate data, and deploy ransomware. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. The attacks, analyzed by Trend Micro’s incident response team, exploit weak passwords and multi-factor authentication (MFA) bypass techniques to infiltrate Check Point firewall VPNs. After establishing persistence, attackers deploy a custom ransomware strain that encrypts files using AES-256 with keys wrapped in RSA-2048.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 20 Feb 2025 17:30:20 +0000