A China-based threat actor, tracked as Emperor Dragonfly and commonly associated with cybercriminal endeavors, has been observed using in a ransomware attack a toolset previously attributed to espionage actors. The hackers deployed the RA World ransomware against an Asian software and services company and demanded an initial ransom payment of $2 million. Researchers from Symantec’s Threat Hunter Team observed the activity in late 2024 and highlight a potential overlap between state-backed cyber espionage actors and financially motivated cybercrime groups. “During the attack in late 2024, the attacker deployed a distinct toolset that had previously been used by a China-linked actor in classic espionage attacks,” the researchers say, adding that "tools associated with China-based espionage groups are often shared resources" but "many aren’t publicly available and aren’t usually associated with cybercrime activity.” A report in July 2024 from Palo Alto Networks’ Unit 42 also associated Emperor Dragonfly (a.k.a. Bronze Starlight) with RA World, albeit with low confidence. According to the researchers, the RA World spun from RA Group, which launched in 2023 as a Babuk-based family. Between July 2024 to January 2025, the China-based espionaged actor targeted government ministries and telecom operators in Southeast Europe and Asia, the apparent goal being long-term persistence. In these attacks, a specific variant of the PlugX (Korplug) backdoor was deployed with a Toshiba executa...
Chinese espionage tools deployed in RA World ransomware attack
BleepingComputer
·Bill Toulas
·Published Feb 13, 2025
·Updated
Affected Software
1 affected component
Palo Alto Networks PAN-OS
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a ransomware attack conducted by a China-based threat actor using espionage tools.
2
Who is the threat actor involved in the ransomware attack?
The threat actor is tracked as Emperor Dragonfly, known for associations with cybercriminal activities.
3
What type of attack did Emperor Dragonfly carry out?
Emperor Dragonfly conducted a ransomware attack deploying espionage-related tools.
4
What software is specifically mentioned as affected in this ransomware attack?
Palo Alto Networks PAN-OS is mentioned as the affected software in the article.
5
What implications does this ransomware attack have for cybersecurity?
The attack highlights the evolving tactics of cybercriminals who are integrating espionage tools into ransomware operations.