Researchers from security firms Profero and Security Joes linked a series of ransomware attacks to the China-linked APT27 group. The hackers used the Windows drive encryption tool BitLocker to lock the servers. The group was involved in cyber espionage campaigns aimed at new generation weapons and in surveillance activities on dissidents and other civilian groups. The recent string of attacks launched by the cyber-espionage group took place in 2020 and aimed at several gambling companies. The researchers also spotted a web shell name ASPXSpy, which is a modified version of this malware.”]
Source: https://securityaffairs.co/wordpress/113000/apt/apt27-ransomware-attacks.html

