DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Sophos Uncovers Chinese Espionage Campaign in Southeast Asia

DigitalCIO Bureau by DigitalCIO Bureau
June 12, 2024
in Tech News
0
Sophos Uncovers Chinese Espionage Campaign in Southeast Asia
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Sophos has released its report, “Operation Crimson Palace:Threat Hunting Unveils Multiple Clusters of Chinese State-Sponsored Activity Targeting Southeast Asia,” which details a highly sophisticated, nearly two-year long espionage campaign against a high-level government target. During Sophos X-Ops’ investigation, which began in 2023, the managed detection and response (MDR) team found three distinct clusters of activity targeting the same organization, two of which included tactics, techniques and procedures (TTPs) that overlap with well-known, Chinese nation-state groups: BackdoorDiplomacy, APT15 and the APT41 subgroup Earth Longzhi.

The attackers designed their operation to gather reconnaissance on specific users as well as sensitive political, economic, and military information, using a wide variety of malware and tools throughout the campaign that Sophos has since dubbed “Crimson Palace.” This includes previously unseen malware: a persistence tool that Sophos named PocoProxy.

“The different clusters appear to have been working in support of Chinese state interests by gathering military and economic intelligence related to the country’s strategies in the South China Sea. In this particular campaign, we believe these three clusters represent distinct groups of attacks who are working in parallel against the same target under the overarching directive of a central state authority. Within just one of the three clusters that we identified—Cluster Alpha— we saw malware and TTPs overlap with four separately reported Chinese threat groups. It’s well-known that Chinese attackers share infrastructure and tooling, and this recent campaign is a reminder of just how extensively these groups share their tools and techniques.

“As Western governments elevate awareness about cyberthreats from China, the overlap Sophos has uncovered is an important reminder that focusing too much on any single Chinese attribution may put organizations at risk of missing trends about how these groups coordinate their operations,” said Paul Jaramillo, director, threat hunting and threat intelligence, Sophos. “By having the bigger, broader picture, organizations can be smarter about their defenses.”

Sophos X-Ops first learned of malicious activity on the targeted organization’s network in December 2022 when they found a data exfiltration tool previously attributed to the Chinese threat group Mustang Panda. From there, the MDR team began a broader hunt for malicious activity. In May 2023, Sophos X-Ops threat hunting uncovered a vulnerable VMWare executable and, after analysis, three distinct clusters of activity in the target’s network: Cluster Bravo, Cluster Charlie and Cluster Alpha.

Cluster Alpha was active from early March to at least August 2023 and deployed a variety of malware focused on disabling AV protections, escalating privileges and conducting reconnaissance. This included an upgraded version of the EAGERBEE malware that has been associated with the Chinese threat group REF5961. Cluster Alpha also utilized TTPs and malware that overlap with the Chinese threat groups BackdoorDiplomacy, APT15, Worok, and TA428.

Cluster Bravo was only active in the targeted network for a three-week span in March 2023 and focused on moving laterally through the victim’s network to sideload a backdoor called CCoreDoor. This backdoor establishes external communications pathways for the attackers, performs discovery and exfiltrates credentials.

Cluster Charlie was active from March 2023 to at least April 2024, with a focus on espionage and exfiltration. This included the deployment of PocoProxy: a persistence tool that masquerades as a Microsoft executable and establishes communications with the attackers’ command and control infrastructure. Cluster Charlie worked to exfiltrate a large volume of sensitive data for espionage purposes, including military and political documents and credentials/tokens for further access within the network. Cluster Charlie shares TTPs with Chinese threat group Earth Longzhi, a reported subgroup of APT41. Unlike Cluster Alpha and Cluster Bravo, Cluster Charlie remains active.

“What we’ve seen with this campaign is the aggressive development of cyberespionage operations in the South China Sea. We have multiple threat groups, likely with unlimited resources, targeting the same high-level government organization for weeks or months at a time, and they are using advanced custom malware intertwined with publicly available tools. They were, and are still, able to move throughout an organization at will, rotating their tools on a frequent basis. At least one of the activity clusters is still very much active and attempting to conduct further surveillance.

“Given how often these Chinese threat groups overlap and share tooling, it’s possible that the TTPs and novel malware we observed in this campaign will resurface in other Chinese operations globally. We will keep the intelligence community informed of what we find as we continue our investigations into these three clusters,” said Jaramillo.

Tags: Sophos
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

NVIDIA Corporation – NVIDIA Enters Production With Dynamo, the Broadly Adopted Inference Operating System for AI Factories

by DigitalCIO Bureau
March 18, 2026
0
NVIDIA Corporation – NVIDIA Enters Production With Dynamo, the Broadly Adopted Inference Operating System for AI Factories

NVIDIA announced NVIDIA Dynamo 1.0, open source software for generative and agentic inference at scale, with widespread global adoption. Together with the NVIDIA Blackwell platform, Dynamo 1.0 enables...

Read moreDetails

TCS and Pearson partner to accelerate AI-powered learning for global industries

by DigitalCIO Bureau
March 18, 2026
0
TCS and Pearson partner to accelerate AI-powered learning for global industries

The multi‑year partnership will help enterprises build future‑ready workforces by combining AI‑powered learning, assessment, and cloud‑led transformation at scale Pearson and Tata Consultancy Services (TCS) have announced a...

Read moreDetails

Hexaware Launches Agentverse, an Enterprise AI Agent Platform with 600+ Ready-to-Deploy Agents

by DigitalCIO Bureau
March 18, 2026
0
Hexaware Launches Agentverse, an Enterprise AI Agent Platform with 600+ Ready-to-Deploy Agents

Agentverse enables enterprises to operationalize agentic AI with 600+ agents across technology and business operations. Hexaware Technologies announced the launch of Agentverse, an enterprise AI agent platform featuring...

Read moreDetails

Cisco Secure AI Factory with NVIDIA Makes AI Easier to Deploy and Secure, Anywhere Organizations Need It

by DigitalCIO Bureau
March 17, 2026
0
Cisco Secure AI Factory with NVIDIA Makes AI Easier to Deploy and Secure, Anywhere Organizations Need It

Expanded architecture lets businesses run AI at scale, from central data centers to the factory floor, without sacrificing performance or security. Cisco announced a major expansion of its...

Read moreDetails

IBM Announces Expanded Collaboration with NVIDIA to Advance AI for the Enterprise

by DigitalCIO Bureau
March 17, 2026
0
IBM Announces Expanded Collaboration with NVIDIA to Advance AI for the Enterprise

Advancements across GPU-native data analytics, unstructured data extraction, on-premises and cloud infrastructure, Nestlé global supply chain decision speed, and consulting to mobilize enterprise AI at scale IBM announced...

Read moreDetails
Next Post
IDC: Public Cloud Investment To Reach $1.35 Trillion In 2027

SentinelOne Transforms Cloud Security For AWS Customers

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Qlik Recognizes Pioneers in Data Innovation at 2024 Global Transformation Awards

Innover Named Rising Star in ISG Provider Lens Report

October 9, 2025
VTEX Partners with Vinculum to Elevate Customer Experience in India

Kyndryl Introduces New Security Edge Services with Cisco

January 31, 2024
Pure Storage Appoints Nathan Hall as VP of Asia Pacific & Japan

Pure Storage Appoints Nathan Hall as VP of Asia Pacific & Japan

September 20, 2023

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?