Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Microsoft says that recently Windows update did not kill your SSD

    August 30, 2025

    I have tested one of the lowest smartwatch that sets only 55 hours of battery life record

    August 30, 2025

    Anthropic detects unavoidable: Jeanai-Keval attack, no human being

    August 30, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Silk typhoon hackers kidnapping network captive portals in diplomatic attacks
    Security

    Silk typhoon hackers kidnapping network captive portals in diplomatic attacks

    PineapplesUpdateBy PineapplesUpdateAugust 27, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Silk typhoon hackers kidnapping network captive portals in diplomatic attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Silk typhoon hackers kidnapping network captive portals in diplomatic attacks

    State-proposed hackers involved in the Silk Typhoon Activity Cluster, abducting web traffic and targeted diplomats by kidnapping on a malware-serving website.

    Hackers used an advanced anti-in-in-media (AITM) technique to hijack the network’s captive portal and sent the target to first-step malware.

    The Google Threat Intelligence Group (GTIG) tracks the danger actor as UnC6384 and based on tooling, targeting and infrastructure, assumes that this Chinese threat is associated with actor Tempax.

    Kidnapping chrome request

    GTIG researchers believe that Aitm was possible after compromising an age device on the target network; However, he did not find evidence to support this principle.

    The attack begins when the Chrome browser checks if it is behind a captive portal, a web page where a network users certify before connecting to the Internet.

    With hackers in the event of kidnapped web traffic, they redirect the target to a landing page, which applies an adobe plugin update site.

    The victims download a digitally signed ‘Adobeplugins.exe’ file, which is presented as an essential plugin update, and directed for step-by-step instructions on the site to bypass Windows safety signs when installing it.

    Fake site indicates adobe plugin installation
    Fake site indicates adobe plugin installation
    Source: Google

    Launching that file displays a Microsoft Visual C ++ Installer, but it secretly downloads a disguised MSI package (20250509.bmp) in which a valid canon printer tool, a DLL (cannstager), and RC-4 encrypted forms contains sagu.SEC backdur.

    The canonstager DLL decips and loads the last payload in the system memory using the side-loading technique.

    Sogu.Sec, which Google says that plugx is a type of malware, which is used extensively by many Chinese danger groups, can collect system information, upload or download files, and provide operative with remote command shells.

    Overview of a series of attacks
    Overview of a series of attacks
    Source: Google

    GTIG researchers noted It is not clear that the Signing Unit used in this campaign, Chengdu Nauzin Times Technology Company, Limited, was deliberately participating or compromised in these works.

    However, GTIG tracks at least 25 malware samples signed by this unit from the beginning of 2023, which is associated with various Chinese activity groups.

    Treating all certificates from Chengdu Nauzin Times Technology Company, Limited has a proper defensive action as incredible until the situation becomes clear.

    Certificate used in latest Mustang Panda campaign
    Certificate used in latest Mustang Panda campaign
    Source: Google

    Google blocked the malicious domain and affected the file hash through safe browsing and issued a government -backed attacker alerts affecting Gmail and workspace users.

    The tech giant has also shared the Yara rules to detect staticPlugin and cannostagers, and indicators of compromise (IOCs) for all files sampled by these attacks.

    This latest campaign is a sign of the growing refinement of Chinese-Naxus detective actors, which are very likely to switch to new infrastructure and binary build and rebound quickly.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    attacks captive diplomatic hackers kidnapping Network portals silk typhoon
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article5 ways to improve cyber security ceremony while spending less
    Next Article This franchise will give you up to $ 100,000 to start a business
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Microsoft says that recently Windows update did not kill your SSD

    August 30, 2025
    Security

    Anthropic detects unavoidable: Jeanai-Keval attack, no human being

    August 30, 2025
    Security

    How a heritage hardware company established itself in the AI ​​era

    August 30, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Microsoft says that recently Windows update did not kill your SSD

    August 30, 2025

    I have tested one of the lowest smartwatch that sets only 55 hours of battery life record

    August 30, 2025

    Anthropic detects unavoidable: Jeanai-Keval attack, no human being

    August 30, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.