Chinese Speaking Threat Actors Leveraging Open-Source Tools to Target East Asia

A series of attacks was discovered infecting organizations in East Asia with SparkRAT, originally an open source tool. TTPs of the attacks point toward the involvement of a Chinese-speaking threat actor dubbed DragonSpark. The Microsoft Security Threat Intelligence team reported about threat actors using SparkRAT for the first time in late December 2022.


>>More