An active campaign in early July that we attribute to a new Chinese APT group attacking India and Hong Kong with MgBot malware. This campaign was most likely carried out through spear phishing emails. The downloaded template uses the dynamic data exchange (DDE) protocol to execute malicious commands, which are encoded within the documents content. The injected payload is a variant of Cobalt Strike. The last document used was Boris Johnson Pledges to Admit 3 Million From Hong Kong to U.K. The file was embedded within an archive file named Mail security check.rar”]

