Cyber security firm ESET observed a notable expansion in targeting by China-aligned MirrorFace, it says in a report. Typically focused on Japanese entities, MirrorFace extended its operations to include a diplomatic organization in the European Union (EU) for the first time while continuing to prioritize its Japanese targets, ESET writes in a report.
Additionally, China-aligned APT groups have been relying increasingly on the open-source and multiplatform SoftEther VPN to maintain access to victims’ networks. We detected extensive use of SoftEther VPN by Flax Typhoon, observed Webworm switching from its full-featured backdoor to using the SoftEther VPN Bridge on machines of governmental organizations in the EU, and noticed GALLIUM deploying SoftEther VPN servers at telecommunications operators in Africa.