Chinese APT group UAT-7237 compromised a Taiwanese web hosting provider using known vulnerabilities on unpatched servers. The group deployed custom malware including SoundBill shellcode loader and used tools like JuicyPotato for privilege escalation, Cobalt Strike for backdoor access, and SoftEther VPN for persistent access.

4m read timeFrom go.theregister.com
Post cover image
Table of contents
More reasons to patch

Sort: