InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Deception in depth: Defending against sophisticated and evolving PRC-nexus espionage campaigns

Presented by

Patrick Whitsell, Security Engineer, Google Threat Intelligence Group and Austin Larsen, Principal Threat Analyst, Google Threat Intelligence Group

About this talk

Join Google Threat Intelligence Group (GTIG) for a deep-dive into the evolving capabilities of PRC-nexus threat actors and actionable recommendations to defend against these attacks. This webinar will provide critical insights and actionable recommendations to defend against the evolving tactics of UNC6384, TEMP.Hex (Mustang Panda), and other PRC-nexus espionage groups. Drawing from extensive experience responding to PRC-nexus threats, we will discuss the various protection mechanisms Google has implemented to protect our users and customers, the curated intelligence offerings in Google Threat Intelligence, and recommendations on hardening networks against these attacks. Google Threat Intelligence Group (GTIG) will also dissect a recently discovered sophisticated, multi-stage cyber espionage campaign that we attributed to the PRC-nexus threat actor UNC6384, which has ties to the prolific threat actor Mustang Panda (TEMP.Hex). The campaign targeted entities around the globe in alignment with the People's Republic of China (PRC) strategic interests. The threat actor leveraged advanced social engineering and captive portal hijacking to deliver a signed malware downloader (STATICPLUGIN), a novel DLL side-loaded launcher (CANONSTAGER), and a memory-only backdoor (SOGU.SEC). This campaign demonstrates the evolving capabilities of PRC-nexus threat actors, highlighting their creative use of stealthy and evasive tactics to avoid detection.
Mandiant | Intelligence and Expertise

Mandiant | Intelligence and Expertise

170273 subscribers147 talks
Make Google part of your security team
Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. By scaling decades of frontline experience, Mandiant helps organizations to be confident in their readiness to defend against and respond to cyber threats. Mandiant is part of Google Cloud.
Related topics