Arctic Wolf Labs uncovered a sophisticated cyber espionage campaign by Chinese-affiliated UNC6384 targeting European diplomatic targets using new Windows exploits and stealth malware. The campaign signifies a strategic shift from Southeast Asia to Europe, aiming to monitor EU defense, infrastructure, and diplomatic activities. #UNC6384 #PlugX
Keypoints
- UNC6384 has shifted its focus from Southeast Asia to European diplomatic targets.
- The campaign exploits the ZDI-CAN-25373 Windows vulnerability to deploy malware.
- Attackers use spearphishing emails with malicious shortcut files and legitimate software for stealth.
- The malware used, PlugX, provides remote access and data exfiltration capabilities.
- New variants of the malware loader are rapidly optimized for detection evasion.