• News/
  • https://www.bleepingcomputer.com/news/security/chinese-espionage-tools-deployed-in-ra-world-ransomware-attack/

Chinese espionage tools deployed in RA World ransomware attack

BleepingComputer
·
Bill Toulas
·
Published Feb 13, 2025
·
Updated

A China-based threat actor, tracked as Emperor Dragonfly and commonly associated with cybercriminal endeavors, has been observed using in a ransomware attack a toolset previously attributed to espionage actors. The hackers deployed the RA World ransomware against an Asian software and services company and demanded an initial ransom payment of $2 million. Researchers from Symantec’s Threat Hunter Team observed the activity in late 2024 and highlight a potential overlap between state-backed cyber espionage actors and financially motivated cybercrime groups. “During the attack in late 2024, the attacker deployed a distinct toolset that had previously been used by a China-linked actor in classic espionage attacks,” the researchers say, adding that "tools associated with China-based espionage groups are often shared resources" but "many aren’t publicly available and aren’t usually associated with cybercrime activity.” A report in July 2024 from Palo Alto Networks’ Unit 42 also associated  Emperor Dragonfly (a.k.a. Bronze Starlight) with RA World, albeit with low confidence. According to the researchers, the RA World spun from RA Group, which launched in 2023 as a Babuk-based family. Between July 2024 to January 2025, the China-based espionaged actor targeted government ministries and telecom operators in Southeast Europe and Asia, the apparent goal being long-term persistence. In these attacks, a specific variant of the PlugX (Korplug) backdoor was deployed with a Toshiba executa...

Read full article

Affected Software

1 affected component
Palo Alto Networks PAN-OS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a ransomware attack conducted by a China-based threat actor using espionage tools.

2

Who is the threat actor involved in the ransomware attack?

The threat actor is tracked as Emperor Dragonfly, known for associations with cybercriminal activities.

3

What type of attack did Emperor Dragonfly carry out?

Emperor Dragonfly conducted a ransomware attack deploying espionage-related tools.

4

What software is specifically mentioned as affected in this ransomware attack?

Palo Alto Networks PAN-OS is mentioned as the affected software in the article.

5

What implications does this ransomware attack have for cybersecurity?

The attack highlights the evolving tactics of cybercriminals who are integrating espionage tools into ransomware operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Chinese espionage tools deployed in RA World ransomware attack - SecAlerts