Chinese APT41 Upgrades Malware Arsenal with DodgeBox and MoonWalk
An "advanced and upgraded version" of a known malware called StealthVector is suspected of being used by the China-linked advanced persistent threat (APT) organization codenamed APT41 to deploy a backdoor known as MoonWalk that was previously unreported.
Zscaler ThreatLabz, which identified the loader strain in April 2024, has named the new StealthVector variant—also known as DUSTPAN—DodgeBox.
According to security researchers Yin Hong Chang and Sudeep Singh, DodgeBox is a loader that loads a new backdoor called MoonWalk. MoonWalk uses Google Drive for command-and-control (C2) communication and shares many of the evasion tactics used in DodgeBox.
The name "APT41" refers to a well-known Chinese state-sponsored threat actor that has been operating actively since at least 2007 read ...

