ThreatConnect Shares Incident Information on Malware Spoofing Domains

Incident Details Chinese APT Malware targeting domains with news themes and sites pertaining to Japan and Taiwan

We have developed TIPpers, which are incidents the ThreatConnect Research team flags for your awareness, so your organization can take decisive action.

TIPper: China APT malware and spoofed domains

ThreatConnect recently identified malware from one of our Chinese Advanced Persistent Threat rules. Upon examining the malware’s command and control (C2) infrastructure, ThreatConnect found a number of spoofed domains registered by the same individual, suggesting these organizations may also be targets. The spoofed domains feature a heavy news theme, as well as a number of sites pertaining to Japan and Taiwan.

For additional details, current ThreatConnect users can access this incident by selecting this LINK or search for incident “20160619A: nick.obama APT” in the ThreatConnect Platform.

If you do not have a ThreatConnect account, click HERE to access our Free Edition as well as 30-day access to our Subscriber Community. ThreatConnect’s Free Edition allows you to establish a basic threat intelligence practice, collaborate with your internal team, protect your organization with open source threat data, bulk import cyberthreat indicators, contribute to the ThreatConnect Community, and receive support and validation from outside researchers and analysts also using the platform.  The Subscriber Community includes timely notification of threat incidents identified by the ThreatConnect Research team, an exclusive service offered at no additional charge to paying customers.

About the Author
ThreatConnect Research Team

The ThreatConnect Research Team: is an elite group of globally-acknowledged cybersecurity experts, dedicated to tracking down existing and emerging cyber threats. We scrutinize trends, technology and socio-political motivators to develop comprehensive knowledge of the cyber landscape. Then, we share what we’ve learned so that you can protect your organization, and your team can take precise action against threats.