APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains
Summary
APT24, a China-nexus threat actor, has been deploying a new malware called BADAUDIO to maintain persistent access to compromised networks over a nearly three-year espionage campaign. This shift to more sophisticated attack vectors poses significant risks to targeted entities, particularly in Taiwan and over 1,000 domains.
Original Article Summary
A China-nexus threat actor known as APT24 has been observed using a previously undocumented malware dubbed BADAUDIO to establish persistent remote access to compromised networks as part of a nearly three-year campaign. "While earlier operations relied on broad strategic web compromises to compromise legitimate websites, APT24 has recently pivoted to using more sophisticated vectors targeting
Impact
Not specified
In the Wild
Yes
Timeline
Ongoing since nearly three years
Remediation
Not specified