Chinese organizations hit by Cobalt Strike malware from China

Cybersecurity researchers at Securonix discovered a new threat campaign involving phishing, DLL sideloading, and Cobalt Strike beacons, all leveraging Tencent’s infrastructure and targeting Chinese entities. Tencent is the largest and most popular cloud service provider in China.

Apparently, the group (which has not been identified and does not appear to be a known organization) sent out phishing emails with attachments discussing “employee lists” and “people who had violated remote control software regulations.”