Threats Tagged 'east asia'
View all threats tagged with 'east asia'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'east asia'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor written in C++. BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY loader as part of a complex attack chain. The backdoor employs advanced techniques including a complex message routing mechanism for C2 communications, EDR evasion to prevent detection of API calls from unbacked executable memory regions, and token manipulation for privilege escalation. Code similarities and shared infrastructure directly connect this activity to the OctLurk backdoor, representing an expansion from Central Asia operations to Middle East targeting with focus on energy sector. The threat actor demonstrates sophisticated development capabilities through custom encryption, modular plugin architecture, and careful operational security measures. Join the discussion | AlienVault OTX General | 08/03/2026, 21:38:36 UTC Added: 07/21/2026, 10:27:03 UTC |
The 'GhostAd' campaign is a large-scale Android adware threat that infiltrated Google Play with seemingly benign apps embedding persistent background advertising engines. These apps exploited Android foreground services, job schedulers, and continuous ad refreshing to maintain presence and aggressively display ads without user interaction, causing significant battery drain, degraded device performance, and difficulty in removal. Although primarily impacting users in East and Southeast Asia, the adware's use of legitimate advertising SDKs complicates detection and removal. Google has removed the malicious apps and disabled them via Google Play Protect. European organizations with Android device fleets could face indirect impacts such as reduced device availability and user productivity if similar apps spread. Mitigation requires proactive app vetting, enhanced endpoint monitoring for abnormal resource usage, and user education on app permissions and removal techniques. Countries with high Android adoption and significant Google Play usage, such as Germany, France, and the UK, are more likely to be affected if the campaign expands. Given the medium severity rating, the threat poses a moderate risk primarily through resource exhaustion and user disruption without direct data compromise or remote exploitation. Join the discussion | AlienVault OTX General | 11/27/2025, 18:32:25 UTC Added: 11/27/2025, 19:03:18 UTC |
APT-C-60 continues to target Japan and East Asia with spear-phishing attacks impersonating job seekers. The attack flow has evolved, now directly attaching malicious VHDX files to emails. The malware, including Downloader1, Downloader2, and SpyGlace, has been updated with new features and communication methods. SpyGlace versions 3.1.12, 3.1.13, and 3.1.14 were observed, with changes in Mutex values and execution paths. The attackers use GitHub for payload distribution and employ sophisticated encoding and encryption techniques. The campaign abuses legitimate services and maintains consistent behavioral patterns despite infrastructure changes. Join the discussion | AlienVault OTX General | 11/05/2025, 08:16:16 UTC Added: 11/05/2025, 08:56:30 UTC |
A recent analysis of a suspicious trojan loader reveals similarities to the APT-C-00 (Ocean Lotus) group, a government-backed hacker organization targeting East Asian companies and government agencies. The sample, a DLL file with excellent evasion capabilities, uses hash algorithms to dynamically obtain API functions. It creates a mutex for single-instance execution, validates command-line parameters, adds itself to the registry for persistence, and sets up a VEH exception handler. The loader employs module hollowing to replace code in certmgr.dll with shellcode that reflectively loads the Havoc RAT. The tactics and development environment align with Ocean Lotus' known techniques, including the use of Mingw-w64 and similar initialization processes. Join the discussion | AlienVault OTX General | 09/22/2025, 08:11:33 UTC Added: 09/22/2025, 19:43:38 UTC |
Showing 1 to 4 of 4 results