Security researchers reported multiple China-linked cyber-espionage operations aimed at Russian-speaking targets, including Russian state-owned defense research institutes within Rostec, a related research entity in Belarus, and systems associated with Russian officials. The campaigns used spear-phishing lures tied to U.S. sanctions, the Ukraine war, biological pathogen themes, and Belarus border tensions to entice victims into opening disguised executables or malicious documents delivered through fake websites and staged downloads.
The intrusions deployed distinct malware families and loaders, including the newly identified SPINNER backdoor and updated PlugX tooling. Researchers said the activity relied on DLL sideloading/search-order hijacking, multi-stage loaders, in-memory decryption, persistence mechanisms, and anti-analysis techniques such as dynamic API resolution and control-flow obfuscation. Check Point assessed the Twisted Panda operation with high confidence as Chinese state-backed espionage with tradecraft overlaps to Mustang Panda and APT10, while Secureworks linked the PlugX activity to BRONZE PRESIDENT, indicating a broader Chinese intelligence effort focused on Russian defense and government-related targets after the invasion of Ukraine.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Check Point said the Twisted Panda espionage activity was observed as recently as April 2022. This indicated the campaign remained active after the March phishing wave.
On March 23, several Russian defense research institutes affiliated with Rostec received spear-phishing emails themed around U.S. sanctions on Russia, while a similar lure about deadly pathogens in Belarus was sent to an entity in Minsk. The emails linked to a fake Russian Health Ministry site and delivered malicious documents.
Secureworks analyzed a March 2022 malicious executable masquerading as a Russian-language document that downloaded a signed executable, a malicious DLL, and an encrypted payload likely to be PlugX. CTU assessed the tradecraft and infrastructure as consistent with the China-based BRONZE PRESIDENT threat group.
Secureworks reported that zyber-i.com was hosted on 103.107.104.19 from March 2 to 13 and served similarly named files used for DLL search order hijacking in a broader PlugX campaign. CTU said the domain had been implicated in targeting European diplomatic entities.
Check Point said the Twisted Panda espionage operation had been active since at least June 2021 as part of a longer-running campaign. The activity was later assessed with high confidence as conducted by a Chinese state-backed threat actor.
Secureworks cited reporting that associated the domain locvnpt.com with attacks against the Vatican that CTU attributed to BRONZE PRESIDENT. It also noted the domain was hosted on 2EZ Networks at IP 167.88.177.151 in September 2020.
Check Point Research published an analysis of the Twisted Panda campaign targeting Russian defense institutes and a Belarus research entity. The report introduced the SPINNER backdoor and assessed the operation as part of a broader Chinese state-sponsored espionage effort with overlaps to Mustang Panda and APT10/Stone Panda tradecraft.
Secureworks CTU published research describing an apparent March 2022 attempt to deploy likely PlugX malware against Russian-speaking targets using DLL side-loading and related infrastructure. The report linked the activity to BRONZE PRESIDENT and provided indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
gbhackers.com
Open sourceresearch.checkpoint.com
Open sourcesecureworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.