APT41 Hackers Use ShadowPad, Cobalt Strike in Taiwanese Institute Cyber Attack

According to new data from Cisco Talos, nation-state threat actors with connections to China compromised a Taiwanese government-affiliated research center that specializes in computers and related technologies.

As early as mid-July 2023, the anonymous group was being targeted to supply a range of backdoors and post-compromise tools, including Cobalt Strike and ShadowPad. With a moderate degree of confidence, it has been linked to the active hacker organization APT41.

Security researchers Joey Chen, Ashley Shen, and Vitor Ventura revealed that the ShadowPad malware employed in the present campaign took advantage of an antiquted, vulnerable version of Microsoft Office IME binary as a loader to load the modified second-stage loader for unleashing the payload read more APT41 Hackers Use ShadowPad Cobalt Strike in Taiwanese Institute Cyber Attack.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *