What stands out is how they stole a real meeting schedule to create a believable fake Webex page. They also added JSONPing to confirm infection before delivering the next payload.
The group is increasing use of DWAgent for post-exploitation and deploying newer backdoors like HttpMalice.
Defense and government teams should watch for suspicious downloads closely.