NG0002 Targets Chinese Academia with Weaponized Institutional Lures
Source: Socprime
Published:
<p>A threat actor tracked as UNG0002 launched a spear-phishing campaign against Chinese universities using a malicious ZIP archive disguised as an official fitness testing notice. Inside the archive was a double-extension LNK file that executed a VBScript, which then used Bandizip to sideload a mali