Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Designing For TV: The Evergreen Pattern That Shapes TV Experiences

      August 27, 2025

      Amplitude launches new self-service capabilities for marketing initiatives

      August 27, 2025

      Microsoft packs Visual Studio August update with smarter AI features

      August 27, 2025

      Optimizing PWAs For Different Display Modes

      August 26, 2025

      How to use GitHub Copilot on github.com: A power user’s guide

      August 27, 2025

      A Radio Button Shopping Cart Trick

      August 27, 2025

      CodeSOD: The HTML Print Value

      August 27, 2025

      Google can translate your voice in real time now – try it free

      August 27, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Password Strength Estimator Validation in Laravel

      August 27, 2025
      Recent

      Password Strength Estimator Validation in Laravel

      August 27, 2025

      Laravel’s Enhanced String Validation with Inverse Methods

      August 27, 2025

      Using SQLite in production with Laravel

      August 27, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      New Apps Arrive in Ubuntu 25.10 Dev Builds

      August 27, 2025
      Recent

      New Apps Arrive in Ubuntu 25.10 Dev Builds

      August 27, 2025

      Rilasciato QEMU 10.1 con Importanti Novità

      August 27, 2025

      Framework Laptop 16: la nuova versione con processori AMD Ryzen AI 300 e scheda grafica NVIDIA GeForce RTX 5070

      August 27, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»China-Linked Espionage Campaign Hijacks Web Traffic to Target Diplomats

    China-Linked Espionage Campaign Hijacks Web Traffic to Target Diplomats

    August 27, 2025

    Espionage Campaign, China, PRC Hackers, Southeast Asia, Diplomats

    Google’s Threat Intelligence Group has uncovered a cyber espionage campaign of a PRC-linked threat actor, which it tracks as UNC6384, using captive portals and adversary-in-the-middle tactics to target diplomats across Southeast Asia.

    Captive portals are the type of sign-in pages familiar to anyone who has logged into hotel Wi-Fi. Instead of leading to a legitimate login, these portals mimicked VPN services or software update pages to deceive victims.

    Once a victim visited, they were served a digitally signed downloader tracked as STATICPLUGIN, which in turn deployed SOGU.SEC, a variant of the notorious PlugX backdoor. PlugX has long been associated with Chinese state-backed intrusion playbook. But this latest variant was delivered through an updated tradecraft designed to avoid detection.

    Technical Details

    • Delivery Mechanism: The malware was signed with a legitimate digital certificate, allowing it to bypass endpoint defenses.

    • Execution Techniques: UNC6384 used indirect execution and adversary-in-the-middle (AitM) techniques to blend with normal traffic and avoid signature-based detection.

    • Data Collection: Once inside, SOGU.SEC enabled lateral movement, file exfiltration, and ongoing surveillance of sensitive diplomatic systems.

    • Infrastructure: The group operated attacker-controlled redirectors, which intercepted traffic and funneled it through malicious portals.

    Espionage Campaign, China, PRC Hackers, Southeast Asia, Diplomats
    Attack Chain (Image Credit: Google Threat Intelligence Group)

    Google said it notified the compromised organizations via government-backed alerts and sharing malicious domains and file hashes that were also added to its Safe Browsing feature.

    Why Diplomats?

    UNC6384’s targeting of diplomats has the geopolitical underpinnings of the campaign. The group zeroed in on government agencies, embassies and foreign service workers operating in Southeast Asia—an area where China has pressing economic and strategic interests. Unlike ransomware or financially motivated operations, this activity reflects the calculated objectives of a nation-state adversary.

    Diplomats are high-value strategic targets. By embedding themselves in their systems, attackers can gain insight into negotiations, policy positions, and alliances. According to recent analysis, Chinese APT groups are increasingly focusing on strategic pre-positioning in critical infrastructure and supply chains, often leveraging edge devices, software frameworks with minimal endpoint defenses, and “living-off-the-land” techniques to ensure persistence and stealth.

    Also read: ‘UNC3886 is Attacking Our Critical Infrastructure Right Now’: Singapore’s National Security Lawmaker

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Miners
    Next Article HOOK Android Trojan Adds Ransomware Overlays, Expands to 107 Remote Commands

    Related Posts

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-50972 – AbanteCart SQL Injection Vulnerability

    August 27, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-50989 – OPNsense Authenticated Command Injection Vulnerability

    August 27, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-5923 – “WordPress Game Review Block Stored Cross-Site Scripting Vulnerability”

    Common Vulnerabilities and Exposures (CVEs)

    vmstat – reports virtual memory statistics

    Linux

    Samsung takes on LG’s best gaming TVs — adds NVIDIA G-SYNC support to 2025 flagship

    News & Updates

    I thought MacOS 15.4.1 was a minor update until it made my iMac better in 4 big ways

    News & Updates

    Highlights

    Artificial Intelligence

    The AI Mantra of All Time to Recite Now!

    April 17, 2025

    It happened to me one afternoon when I was sipping chai and pondering the future…

    Beyond Basics: Unlocking the Power of Advanced Bash Scripting

    May 15, 2025

    Alibaba Introduces Group Sequence Policy Optimization (GSPO): An Efficient Reinforcement Learning Algorithm that Powers the Qwen3 Models

    August 7, 2025

    This city is the latest European government to dump Microsoft for Linux

    June 27, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.