Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign

An abandoned update server associated with input method editor (IME) software Sogou Zhuyin was leveraged by threat actors as part of an espionage campaign to deliver several malware families, including C6DOOR and GTELAM, in attacks primarily targeting users across Eastern Asia.
“Attackers employed sophisticated infection chains, such as hijacked software updates and fake cloud storage or login

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Can Your Security Stack See ChatGPT? Why Network Visibility Matters

Next Post

Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication

Related Posts
Total
0
Share