I-Soon: Operation FishMedley
by sovrvltn - Tuesday March 25, 2025 at 10:36 AM
#1
"FishMonger – a group believed to be operated by the Chinese contractor I‑SOON (see our Q4 2023-Q1 2024 APT Activity Report) – falls under the Winnti Group umbrella and is most likely operating out of China, from the city of Chengdu where I‑SOON’s office was located. FishMonger is also known as Earth Lusca, TAG‑22, Aquatic Panda, or Red Dev 10. We published an analysis of this group in early 2020 when it heavily targeted universities in Hong Kong during the civic protests that started in June 2019. We initially attributed the incident to Winnti Group but have since revised our attribution to FishMonger.

The group is known to operate watering-hole attacks, as reported by Trend Micro. FishMonger’s toolset includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, SprySOCKS, and the BIOPASS RAT."

https://www.welivesecurity.com/en/eset-r...ishmedley/
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Im Tanaka, and i am using real email (moderator of PwnForums and DarkForums) unret 1 152 9 hours ago
Last Post: digits
  Brent crude oil. dai5 2 275 Yesterday, 11:21 AM
Last Post: phas3lock
  Where to buy cheap Monopoly Go Stickers? IGGM is the best choice. Kingloud 0 110 Yesterday, 10:42 AM
Last Post: Kingloud
  Have You Experienced All The New Content in Diablo 4 Season 13 and Lord of Hatred? Kingloud 0 98 Yesterday, 10:31 AM
Last Post: Kingloud
  IGGM - Best Choice to Buy MLB The Show 26 Stubs Kingloud 0 98 Yesterday, 10:21 AM
Last Post: Kingloud

Forum Jump:


 Users browsing this forum: 1 Guest(s)