Between 2021 and 2023, ransomware and data encryption assaults targeting government and critical infrastructure sectors worldwide have been attributed to threat actors suspected of having ties to China and North Korea.
The cybersecurity companies SentinelOne and Recorded Future said in a joint report with The Hacker News that while one cluster of activity has been linked to the ChamelGang (also known as CamoFei), the second cluster overlaps with activity that has previously been linked to state-sponsored groups in China and North Korea.
This includes the 2022 CatB ransomware assaults by ChamelGang against the All India Institute of Medical Sciences (AIIMS) and the Brazilian Presidency, in addition to strikes on an East Asian government and an Indian subcontinent aviation company.
Security researchers Aleksandar Milenkoski and Julian-Ferdinand Vögele noted that threat actors in the cyber espionage ecosystem read more about Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware.
cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
