Symantec security researchers have discovered a new APT hacking group (Grayling) that has primarily attacked Taiwanese organizations , as part of a cyberespionage campaign that lasted at least four months.
Symantec named the campaign and hacking group “ Grayling ” and reported that the malicious activity began in February 2023 and continued until at least May 2023. During this time, the hackers stole sensitive information from manufacturing, technology , and biomedical companies in Taiwan, while there were also victims in other regions (United States, Vietnam, and Pacific Islands).

The group used DLL sideloading via the exported API “SbieDll_Hook” to load tools such as Cobalt Strike Stager, which led to the popular Cobalt Strike Beacon. The hackers also installed “Havoc,” an open-source, post-exploitation command-and-control (C2) framework, which is used in a similar way to Cobalt Strike.
See also: 23andMe: Hacker has stolen users' genetic information
According to the report, the Grayling group used the NetSpy, exploited an old Windows bug (CVE-2019-0803), and downloaded and executed shellcode.
Additionally, as Symantec researchers say, the hackers stop all processes listed in a file called processlist.txt and download the credential stealing tool, Mimikatz.
“Although we do not see any data being extracted from the victims' machines, the activity we see and the tools being deployed indicate that the motive behind this activity is information gathering“.
The researchers explain that the Grayling group's modus operandi is typical of APT groups. These groups use both custom and publicly available tools (the latter helping to evade detection). Havoc and Cobalt Strike are particularly useful, offering a wide range of post-exploitation capabilities.
See also: Spyhide: Another top mobile spyware has been taken down
Symantec says that many hackers (even experienced ones) choose tools that are available to everyone, rather than custom tools with similar capabilities. Using these tools can also make it more difficult to attribute malicious activity to a specific hacking group.
The company does not link the hackers to any specific government, but Grayling's goals align with Beijing's geopolitical interests.
Protection from hackers
In the modern era of digital technology , cybersecurity training has become essential for businesses. Therefore, businesses must emphasize informing and educating employees against threats.

Identifying intimate threats and violations
Both IT teams and other employees need to be aware of common forms of cyberattacks. It is also essential to be aware of the latest techniques used by hackers:
- Phishing: Attackers often send fake emails that look official to solicit personal information.
- Malware: Programs that are installed without the user's permission and can destroy files or steal information.
- Ransomware: A type of malware that encrypts files and demands a ransom for their decryption.
See also: LightSpy iPhone spyware: Is it linked to APT41 hackers?
Training tactics
Just like in the real world, threats in the digital world are evolving and changing rapidly. Should we be constantly alert and prepared for this evolution? Can we effectively address this risk even if we are not cybersecurity experts?
- Continuous Update: Cybersecurity training should not be done just once. Regular updates and frequent repetition are essential.
- Practical Experience: In order for employees to fully understand the risks, it may be helpful to have some real-world exposure to cyberthreats (e.g., participating in phishing attack tests with the approval and supervision of experts).
- Create guidelines: Guidelines for securely accessing and using business resources are essential. They should include information on strong passwords, protecting personal information, and recognizing phishing messages.
Source: www.infosecurity-magazine.com
