Join Google Threat Intelligence Group (GTIG) for a deep-dive into the evolving capabilities of PRC-nexus threat actors and actionable recommendations to defend against these attacks.
This webinar will provide critical insights and actionable recommendations to defend against the evolving tactics of UNC6384, TEMP.Hex (Mustang Panda), and other PRC-nexus espionage groups. Drawing from extensive experience responding to PRC-nexus threats, we will discuss the various protection mechanisms Google has implemented to protect our users and customers, the curated intelligence offerings in Google Threat Intelligence, and recommendations on hardening networks against these attacks.
Google Threat Intelligence Group (GTIG) will also dissect a recently discovered sophisticated, multi-stage cyber espionage campaign that we attributed to the PRC-nexus threat actor UNC6384, which has ties to the prolific threat actor Mustang Panda (TEMP.Hex). The campaign targeted entities around the globe in alignment with the People's Republic of China (PRC) strategic interests. The threat actor leveraged advanced social engineering and captive portal hijacking to deliver a signed malware downloader (STATICPLUGIN), a novel DLL side-loaded launcher (CANONSTAGER), and a memory-only backdoor (SOGU.SEC). This campaign demonstrates the evolving capabilities of PRC-nexus threat actors, highlighting their creative use of stealthy and evasive tactics to avoid detection.