In an effort to further Beijing’s geopolitical objectives, a group of attacks targeting embassies in Southeast Asia and other organizations worldwide have been traced to a China-nexus threat actor identified as UNC6384.
According to Patrick Whitsell, a researcher at Google Threat Intelligence Group (GTIG), this multi-stage assault chain uses sophisticated social engineering techniques to avoid detection, such as genuine code signing certificates, an adversary-in-the-middle (AitM) attack, and indirect execution methods.
A well-known Chinese hacker collective known as Mustang Panda—also known as BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, RedDelta, Red Lich, Stately Taurus, TEMP.Hex, and Twill Typhoon—is thought to have tactical and tooling similarities with UNC6384.
The campaign, which GTIG discovered in March 2025, is distinguished by its use of a captive portal redirect to divert online traffic and distribute STATICPLUGIN a digitally signed downloader read more about UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
