QiAnXin Threat Intelligence Center and Falcon Operations Team observed in their daily operations that in June 2024, several foreign counterparts reported in-the-wild attacks related to the new attack technique GrimResource.
QiAnXin Threat Intelligence Center and Falcon Operations Team promptly conducted research on this technique and have been continuously monitoring it. In mid-July 2024, they discovered the first attack incident in government and enterprise terminals, and the researchers classified the nature of the attack as black industry. The GrimResource technique exploits the XSS vulnerability in mmc system files to execute JS code and uses DotNetToJScript to load arbitrary .NET programs into memory. This not only bypasses ActiveX control warnings but also enables fileless payload execution.
Read more…
Source: QiAnXin Threat Intelligence Center/Falcon Operations Team
Related:
- Government-backed actors exploiting WinRAR vulnerability
October 18, 2023
In recent weeks, Google’s Threat Analysis Group’s (TAG) has observed multiple government-backed hacking groups exploiting the known vulnerability, CVE-2023-38831, in WinRAR, which is a popular file archiver tool for Windows. Cybercrime groups began exploiting the vulnerability in early 2023, when the bug was still unknown to defenders. A patch is now available, but many users still ...
- China’s cyber security association sets up special committee to bolster AI research
October 15, 2023
China has set up a professional committee focusing on governance of artificial intelligence (AI) security in a bid to build a sustained foundation for the sound development of the emerging industry, according to the country’s cyber security association. On Thursday, an inaugural meeting was held in Beijing for the AI security governance committee under the ...
- Stayin’ Alive – targeted attacks against telecoms and government ministries in Asia
October 11, 2023
In the last few months, Check Point Research has been tracking “Stayin’ Alive”, an ongoing campaign that has been active since at least 2021. The campaign operates in Asia, primarily targeting the Telecom industry, as well as government organizations. The “Stayin’ Alive” campaign consists of mostly downloaders and loaders, some of which are used as ...
- India: Territorial Army hires Chinese language interpreters, to induct cyber security experts next
October 8, 2023
The Indian Army, in its plan for larger manpower optimisation of its force, is deliberating to convert its logistics and transport units into the Territorial Army (TA), a top defence source said Thursday. The TA, according to the source, is also recruiting Chinese language interpreters for border personnel meetings (BPM) and cyber security experts to ...
- Taiwan prosecutors investigating alleged submarine program leak
October 3, 2023
Prosecutors yesterday said they are investigating accusations of interference with the nation’s submarine program and that details of it were leaked, in what would be a serious breach of national security. Taiwan unveiled its first domestically developed submarine on Thursday last week, a major step in a project aimed at bolstering the nation’s defense and deterrence ...
- U.S. DoD’s Critical Infrastructure Is Dangerously Insecure
October 2, 2023
As simmering tensions in East Asia rise to a boil, the recent discovery of a Chinese penetration of the U.S. military’s telecommunication systems in Guam should be setting off alarm bells across the executive branch and in the halls of Congress. Though Chinese penetration of U.S. networks for espionage has been well documented for more than ...

