Chinese-linked APT41 deploys stealthy Linux backdoor to target cloud platforms
Once inside a system, the malware targets cloud metadata services to extract temporary credentials.
CERT-UA believes the attacks may also target individuals connected to Ukraineu2019s Defense Forces
Once inside a system, the malware targets cloud metadata services to extract temporary credentials.
In addition to the SharePoint zero-day, Microsoft also patched a publicly disclosed privilege-escalation flaw.
There are no other public reports so far confirming active exploitation of CVE-2020-9715, CVE-2023-36424, or CVE-2025-60710 besides CISAu2019s KEV list.
Researchers found that 54 of the extensions specifically target Google account data using OAuth2, while 45 include a hidden backdoor.
The hackers used a tactic called u201cpretexting,u201d tricking victims into downloading a fake PDF viewer.
Authorities also detained the alleged developer of the operation and seized key domains linked to the scheme.