Red Ladon Poisons Australian News Sites with ScanBox Keyloggers
Click that 'Sick Leave' email from Australian Morning News. Boom—your keystrokes are ScanBox's. China's Red Ladon just dusted off a 10-year-old trick for fresh espionage.
Threat DigestApr 03, 20263 min read
⚡ Key Takeaways
Red Ladon uses ScanBox in watering holes mimicking Aussie news to keylog without disk malware.𝕏
WebRTC/STUN enables NAT traversal, turning browsers into stealth C2 channels.𝕏
Ties to China's MSS signal South China Sea cyber-escalation; expect broader use.𝕏
The 60-Second TL;DR
Red Ladon uses ScanBox in watering holes mimicking Aussie news to keylog without disk malware.
WebRTC/STUN enables NAT traversal, turning browsers into stealth C2 channels.
Ties to China's MSS signal South China Sea cyber-escalation; expect broader use.