{"id":3894,"date":"2024-06-05T05:30:00","date_gmt":"2024-06-05T10:30:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/chinese-threat-clusters-triple-team-high-profile-asian-government-org"},"modified":"2024-06-05T05:30:00","modified_gmt":"2024-06-05T10:30:00","slug":"chinese-threat-clusters-triple-team-a-high-profile-asia-government-org","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/05\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org\/","title":{"rendered":"Chinese Threat Clusters Triple-Team a High-Profile Asia Government Org"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltf3e695922be1142f\/66588ad160fbca02821c05f4\/Wrestling-Vishal_Somaiya-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Over the past year, a trio of Chinese state-aligned threat clusters collaborated to glean sensitive military and political secrets from a high-profile government organization in Southeast Asia.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A new Sophos report highlights not just the sophistication of the so-called &#8220;Operation Crimson Palace&#8221; \u2014 involving new malware tools, more than 15 dynamic link library (DLL) sideloading efforts, and some novel evasion techniques \u2014 but also a remarkable degree of coordination. Three different threat clusters performed specialized tasks in a broader attack chain, likely under the watch of a single organization.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Such diligent teamwork allowed the attackers to steal a large number of files and emails. Those files and emails included, for example, documents outlining strategic approaches to the hotly contested South China Sea. The unidentified government in question has long feuded with China over that territory.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Operation Crimson Palace\">Operation Crimson Palace<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Chinese advanced persistent threats (APTs) have been known to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/chinese-orb-networks-conceal-apts-make-tracking-iocs-irrelevant\" rel=\"noopener\">share infrastructure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/new-spookier-gh0st-rat-uzbekistan-south-korea\" rel=\"noopener\">malicious code<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, but Operation Crimson Palace takes inter-APT collaboration to new heights.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first signs of Chinese-linked threat activity can be traced at least to March 2022, when the &#8220;Nupakage&#8221; data exfiltration tool <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/amid-military-buildup-china-deploys-mustang-panda-in-the-philippines\" rel=\"noopener\">developed by Mustang Panda<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (aka Bronze President, Camaro Dragon, Earth Preta, Luminous Moth, Red Delta, Stately Taurus) was deployed to the victim government&#8217;s network. Later, in December, an attacker performed DLL stitching to covertly deploy two backdoors against targeted domain controllers. Exactly who was behind this first year of activity is as yet unclear.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Crimson Palace campaign began the following year, with the team Sophos calls Cluster Alpha. From March through August 2023, Alpha performed reconnaissance by mapping server subnets, noting administrator accounts, and probing Active Directory infrastructure. It disabled antivirus protections, including by using a new variant of the Eagerbee backdoor from <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/linux-support-expands-cyber-spy-groups-arsenal\" rel=\"noopener\">Emissary Panda<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (aka Iron Tiger, APT27). It also performed various steps toward establishing persistence, leveraging uncommon LOLbins and no less than five different malware tools for command and control (C2).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cluster Bravo had a quicker job. Entering the fray in March and leaving after just a few weeks, it focused primarily on using legitimate accounts to spread laterally in the target&#8217;s network. To aid in this effort, as well as establishing C2 communications and dumping credentials, Bravo deployed a novel backdoor, called CCoreDoor.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The final cluster, Charlie, proved the most troublesome. From March 2023 to April 2024 it specialized in access management \u2014 performing ping sweeps across the network to map all users and endpoints, and capturing credentials from domain controllers \u2014 and deployed a novel backdoor called PocoProxy for C2 purposes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Most importantly, Charlie collected and exfiltrated large volumes of data. The information gleaned from the government network included sensitive military and political secrets, including documents outlining strategic approaches to the hotly contested South China Sea.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Whodunit? Who Cares?\">Whodunit? Who Cares?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Operation Crimson Palace involved tools and infrastructure that overlap with some half dozen known Chinese threat actors, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/mysterious-worok-spy-obfuscated-code-private-tools\" rel=\"noopener\">most notably Worok<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/apt41-subgroup-plows-through-asia-pacific-utilizing-layered-stealth-tactics\" rel=\"noopener\">the APT41 subgroup Earth Longzhi<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Sophos researchers used this and the nature of the espionage to tie the attack to the Chinese government, but stopped short of attributing a specific group.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In fact, they say, focusing on attributing Crimson Palace might end up being counterproductive to defending against it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I think this has been problematic in the past \u2014 we obsess too much with attribution,&#8221; says Chester Wisniewski, director and global field CTO at Sophos. Attribution can make defenders feel like they can predict an attacker&#8217;s next moves but, as Crimson Palace demonstrates, &#8220;Just because one group is really talented at one given thing does not mean you&#8217;re not going to see completely different techniques used later,&#8221; Wisniewski says. &#8220;Because they may have shared those stolen credentials with other groups, with completely different tool sets and completely different missions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Once you&#8217;re breached by one of these adversaries, all bets are off. One group might be after espionage. Another one might be prepositioning for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/china-s-volt-typhoon-apt-burrows-us-critical-infrastructure\" rel=\"noopener\">Volt Typhoon-style future disruption<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. You have to assume all those things are happening.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/chinese-threat-clusters-triple-team-high-profile-asian-government-org\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the past year, a trio of Chinese state-aligned threat<\/p>\n","protected":false},"author":12,"featured_media":3895,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3894","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?fit=2560%2C1920&ssl=1",2560,1920,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?fit=300%2C225&ssl=1",300,225,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?fit=640%2C480&ssl=1",640,480,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?fit=640%2C480&ssl=1",640,480,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?fit=1536%2C1152&ssl=1",1536,1152,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?fit=2048%2C1536&ssl=1",2048,1536,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?fit=1024%2C768&ssl=1",1024,768,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/chinese-threat-clusters-triple-team-a-high-profile-asia-government-org-scaled.jpg?fit=2560%2C1920&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3894","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3894"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3894\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3895"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}