A new sophisticated malware campaign, which utilizes geographic mapping technology (Geo-Mapping Tool), has put critical infrastructure and corporate networks on alert.

According to researchers, the campaign began targeting various sectors in Asia and North America and is allegedly linked to a group of Chinese hackers that uses advanced obfuscation tactics to maintain a prolonged presence on the network.
See also: Vulnerability in Microsoft IIS allows malicious code execution
The attackers leveraged a unique combination of legitimate mapping tools and custom remote access (RATs), which allowed them to bypass detection and exploit geographic data for lateral movement within compromised environments.
Geo-Mapping Tool Abuse: How does the attack work?
Initial infection occurs via spear-phishing emails with Trojan horse attachments. Once activated, the malicious payload executes scripts that secretly download mapping data and commands from servers controlled by the attackers. The infection chain embeds itself in trusted local services—often using digital certificates that impersonate well-known vendors—thus bypassing basic endpoint and network defenses.
The breaches, documented by Reliaquest researchers, revealed integration into existing network traffic, with payloads designed to appear as legitimate updates or geographic information software add-ons.

Reliaquest analysts noted that the malware managed to remain undetected on victim networks for over twelve months. The researchers highlighted the methodical use of geo-mapping metadata, which enabled targeted monitoring and mapping of resources, helping attackers evade geo-restriction-based security checks and remain undetected for extended periods.
See also: NoName057(16) attacks public works procurement platform
Central to the malware's success was its flexible infection routine. The threat actors embedded PowerShell and VBScript code snippets into Microsoft Office documents, ensuring automatic execution upon opening.
One of the scripts, seen by the researchers, downloaded and launched the malicious geo-mapping executable, disguised as a software component. Once installed, the malware established persistence via scheduled tasks and registry keys.
As mentioned above, the attackers also used custom RAT modules, which dynamically referenced local network maps, performing discovery operations and periodic communication with the C2 infrastructure.
See also: Vulnerability in FortiOS allows execution of system commands

Security teams are urged to monitor for strange scheduling routines and network traffic involving mapping utilities, as these behaviors often precede prolonged breaches.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
