Malspace
On this episode, Mark Parsons, Senior Threat Hunter at Sophos MDR, discusses his team's investigation into Operation Crimson Palace, which uncovered Chinese state-sponsored cyberespionage targeting a Southeast Asian government. Mark explains how they identified three distinct clusters of activity using advanced malware and evasion techniques, including previously unreported tools like CCoreDoor and PocoProxy. Show Notes * Operation Crimson Palace: Sophos threat hunting unveils multiple clusters of Chinese state-sponsored activity targeting Southeast Asian government [https://news.sophos.com/en-us/2024/06/05/operation-crimson-palace-sophos-threat-hunting-unveils-multiple-clusters-of-chinese-state-sponsored-activity-targeting-southeast-asia/] * Surfacing a Hydra: Unveiling a Multi-Headed Chinese State-Sponsored Campaign Against a Foreign Government [https://www.blackhat.com/us-24/briefings/schedule/index.html#surfacing-a-hydra-unveiling-a-multi-headed-chinese-state-sponsored-campaign-against-a-foreign-government-39319] * Crimson Palace returns: New Tools, Tactics, and Targets [https://news.sophos.com/en-us/2024/09/10/crimson-palace-new-tools-tactics-targets/]
9 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y forma parte de la comunidad de Malspace!