Friday, May 9, 2025
  • Login
No Result
View All Result
ForexTV
  • News
    • Top Corporate News
    • Lifestyle
    • Technology
    • Financial Markets News
  • Small Business
    • Digital Marketing Blog
    • Small Business Best Practices
    • Small Business Strategy
      • Sales Strategies
      • Marketing Strategies
  • Business Finance
    • Small Business-Lending Trends
    • Debt Service Coverage Ratio (DSCR)
    • Business Credit
      • Business Credit Blog
      • Business Loans
      • Merchant Cash Advances
      • Business Line of Credit
      • What is Alternative Business Lending?
    • Resources
      • Debt Service Coverage Ratio (DSCR) Calculator
  • Currency Focus
    • Crypto Focus
      • Bitcoin (BTC)
      • Ethereum (ETH)
      • Tether
      • BNB
      • Cardano (Ada)
      • Ripple (XRP)
      • Solana (SOL)
      • Dogecoin (DOGE)
      • Polkadot (DOT)
      • Tron (TRX)
      • Shiba Inu (SHIB)
      • Litecoin (LTC)
    • EURO (EUR)
    • Japanese Yen (JPY)
    • Great British Pound (GBP)
    • Swiss Franc (CHF)
    • New Zealand Dollar (NZD)
    • Canadian Dollar (CAD)
    • Australian Dollar (AUD)
  • Resources
    • Economic Calendar
    • Trader Education
      • Candlestick Pattern Intro
    • Live Forex Rates/Charts
      • Live Rates
      • Live Charts
    • Forex Trader Tools
      • Pivot Point Calculator
      • Currency Converter
      • Global Statistic Resources
    • Trading Terms
      • Forex Glossary
      • Glossary of Retirement Industry Terms
    • CPI Tools
      • CPI Inflation Calculator
      • CPI Average Price Calculator
  • Marketing Services
    • Digital Marketing Services
    • Digital Marketing Consulting
    • Search Engine Optimization (SEO)
    • Online Content Marketing
    • Digital Marketing Blog
    • Inbound Marketing Services
    • Email Marketing
    • Digital Marketing Rates
  • News
    • Top Corporate News
    • Lifestyle
    • Technology
    • Financial Markets News
  • Small Business
    • Digital Marketing Blog
    • Small Business Best Practices
    • Small Business Strategy
      • Sales Strategies
      • Marketing Strategies
  • Business Finance
    • Small Business-Lending Trends
    • Debt Service Coverage Ratio (DSCR)
    • Business Credit
      • Business Credit Blog
      • Business Loans
      • Merchant Cash Advances
      • Business Line of Credit
      • What is Alternative Business Lending?
    • Resources
      • Debt Service Coverage Ratio (DSCR) Calculator
  • Currency Focus
    • Crypto Focus
      • Bitcoin (BTC)
      • Ethereum (ETH)
      • Tether
      • BNB
      • Cardano (Ada)
      • Ripple (XRP)
      • Solana (SOL)
      • Dogecoin (DOGE)
      • Polkadot (DOT)
      • Tron (TRX)
      • Shiba Inu (SHIB)
      • Litecoin (LTC)
    • EURO (EUR)
    • Japanese Yen (JPY)
    • Great British Pound (GBP)
    • Swiss Franc (CHF)
    • New Zealand Dollar (NZD)
    • Canadian Dollar (CAD)
    • Australian Dollar (AUD)
  • Resources
    • Economic Calendar
    • Trader Education
      • Candlestick Pattern Intro
    • Live Forex Rates/Charts
      • Live Rates
      • Live Charts
    • Forex Trader Tools
      • Pivot Point Calculator
      • Currency Converter
      • Global Statistic Resources
    • Trading Terms
      • Forex Glossary
      • Glossary of Retirement Industry Terms
    • CPI Tools
      • CPI Inflation Calculator
      • CPI Average Price Calculator
  • Marketing Services
    • Digital Marketing Services
    • Digital Marketing Consulting
    • Search Engine Optimization (SEO)
    • Online Content Marketing
    • Digital Marketing Blog
    • Inbound Marketing Services
    • Email Marketing
    • Digital Marketing Rates
No Result
View All Result
ForexTV
No Result
View All Result
ADVERTISEMENTS
club Felene

Sophos Uncovers Chinese Espionage Campaign in Southeast Asia

by GlobeNewswire
June 5, 2024
in Top News
Reading Time: 4 mins read

Sophos X-Ops Finds Links Between Five Well-Known Chinese Threat Groups, Including APT41 and BackdoorDiplomacy

Chinese Attackers Leverage Previously Unseen Malware for Espionage and Persistence

OXFORD, United Kingdom, June 05, 2024 (GLOBE NEWSWIRE) — Sophos, a global leader of innovative security solutions for defeating cyberattacks, today released its report, “Operation Crimson Palace: Threat Hunting Unveils Multiple Clusters of Chinese State-Sponsored Activity Targeting Southeast Asia,” which details a highly sophisticated, nearly two-year long espionage campaign against a high-level government target. During Sophos X-Ops’ investigation, which began in 2023, the managed detection and response (MDR) team found three distinct clusters of activity targeting the same organization, two of which included tactics, techniques and procedures (TTPs) that overlap with well-known, Chinese nation-state groups: BackdoorDiplomacy, APT15 and the APT41 subgroup Earth Longzhi.

The attackers designed their operation to gather reconnaissance on specific users as well as sensitive political, economic, and military information, using a wide variety of malware and tools throughout the campaign that Sophos has since dubbed “Crimson Palace.” This includes previously unseen malware: a persistence tool that Sophos named PocoProxy.

“The different clusters appear to have been working in support of Chinese state interests by gathering military and economic intelligence related to the country’s strategies in the South China Sea. In this particular campaign, we believe these three clusters represent distinct groups of attacks who are working in parallel against the same target under the overarching directive of a central state authority. Within just one of the three clusters that we identified—Cluster Alpha— we saw malware and TTPs overlap with four separately reported Chinese threat groups. It’s well-known that Chinese attackers share infrastructure and tooling, and this recent campaign is a reminder of just how extensively these groups share their tools and techniques.

“As Western governments elevate awareness about cyberthreats from China, the overlap Sophos has uncovered is an important reminder that focusing too much on any single Chinese attribution may put organizations at risk of missing trends about how these groups coordinate their operations,” said Paul Jaramillo, director, threat hunting and threat intelligence, Sophos. “By having the bigger, broader picture, organizations can be smarter about their defenses.”

Sophos X-Ops first learned of malicious activity on the targeted organization’s network in December 2022 when they found a data exfiltration tool previously attributed to the Chinese threat group Mustang Panda. From there, the MDR team began a broader hunt for malicious activity. In May 2023, Sophos X-Ops threat hunting uncovered a vulnerable VMWare executable and, after analysis, three distinct clusters of activity in the target’s network: Cluster Bravo, Cluster Charlie and Cluster Alpha.

Cluster Alpha was active from early March to at least August 2023 and deployed a variety of malware focused on disabling AV protections, escalating privileges and conducting reconnaissance. This included an upgraded version of the EAGERBEE malware that has been associated with the Chinese threat group REF5961. Cluster Alpha also utilized TTPs and malware that overlap with the Chinese threat groups BackdoorDiplomacy, APT15, Worok, and TA428.

Cluster Bravo was only active in the targeted network for a three-week span in March 2023 and focused on moving laterally through the victim’s network to sideload a backdoor called CCoreDoor. This backdoor establishes external communications pathways for the attackers, performs discovery and exfiltrates credentials.

Cluster Charlie was active from March 2023 to at least April 2024, with a focus on espionage and exfiltration. This included the deployment of PocoProxy: a persistence tool that masquerades as a Microsoft executable and establishes communications with the attackers’ command and control infrastructure. Cluster Charlie worked to exfiltrate a large volume of sensitive data for espionage purposes, including military and political documents and credentials/tokens for further access within the network. Cluster Charlie shares TTPs with Chinese threat group Earth Longzhi, a reported subgroup of APT41. Unlike Cluster Alpha and Cluster Bravo, Cluster Charlie remains active.

“What we’ve seen with this campaign is the aggressive development of cyberespionage operations in the South China Sea. We have multiple threat groups, likely with unlimited resources, targeting the same high-level government organization for weeks or months at a time, and they are using advanced custom malware intertwined with publicly available tools. They were, and are still, able to move throughout an organization at will, rotating their tools on a frequent basis. At least one of the activity clusters is still very much active and attempting to conduct further surveillance.

“Given how often these Chinese threat groups overlap and share tooling, it’s possible that the TTPs and novel malware we observed in this campaign will resurface in other Chinese operations globally. We will keep the intelligence community informed of what we find as we continue our investigations into these three clusters,” said Jaramillo.

Read more about this espionage campaign in “Operation Crimson Palace: Threat Hunting Unveils Multiple Clusters of Chinese State-Sponsored Activity Targeting Southeast Asia” on Sophos.com.

Learn more about the three activity clusters in “Operation Crimson Palace: A Technical Deep Dive” on Sophos.com.

Learn More About

  • The latest techniques, tactics and procedures (TTPs) of cyber attackers in the Active Adversary Report for 1H 2024
  • The biggest threats against small- and medium-sized businesses in the 2024 Sophos Threat Report
  • The use of threat activity clusters to identify patterns of malicious activity
  • Sophos X-Ops and its groundbreaking threat research by subscribing to the Sophos X-Ops blogs

About Sophos
Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks, including Managed Detection and Response (MDR) and incident response services and a broad portfolio of endpoint, network, email, and cloud security technologies. As one of the largest pure-play cybersecurity providers, Sophos defends more than 600,000 organizations and more than 100 million users worldwide from active adversaries, ransomware, phishing, malware, and more. Sophos’ services and products connect through the Sophos Central management console and are powered by Sophos X-Ops, the company’s cross-domain threat intelligence unit. Sophos X-Ops intelligence optimizes the entire Sophos Adaptive Cybersecurity Ecosystem, which includes a centralized data lake that leverages a rich set of open APIs available to customers, partners, developers, and other cybersecurity and information technology vendors. Sophos provides cybersecurity-as-a-service to organizations needing fully managed security solutions. Customers can also manage their cybersecurity directly with Sophos’ security operations platform or use a hybrid approach by supplementing their in-house teams with Sophos’ services, including threat hunting and remediation. Sophos sells through reseller partners and managed service providers (MSPs) worldwide. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.

CONTACT: Contact: Samantha Powers, sophos@walkersands.com

  • Author
  • Recent Posts
GlobeNewswire
GlobeNewswire
GlobeNewswire,is one of the world's largest newswire distribution networks, specializing in the delivery of corporate press releases financial disclosures and multimedia content to the media, investment community, individual investors and the general public.
GlobeNewswire
Latest posts by GlobeNewswire (see all)
  • Montclair Pediatric Dentistry Sets a New Standard in Compassionate Pediatric Dental Care Across the Bay Area - May 9, 2025
  • Boys & Girls Clubs of America Celebrates Its Esteemed Alumni Hall of Fame Class - May 9, 2025
  • Conifer Gutter Service Unveils Dependable Solutions for Year-Round Home Protection - May 9, 2025
ADVERTISEMENTS

Related Posts

Montclair Pediatric Dentistry Sets a New Standard in Compassionate Pediatric Dental Care Across the Bay Area

by GlobeNewswire
May 9, 2025
0

Oakland, May 09, 2025 (GLOBE NEWSWIRE) -- Oakland, California - Oakland, CA – Montclair Pediatric Dentistry is quickly becoming the...

Boys & Girls Clubs of America Celebrates Its Esteemed Alumni Hall of Fame Class

by GlobeNewswire
May 9, 2025
0

Honorees from Sports, Entertainment, Healthcare and More Inducted During May 8 Ceremony, Hosted by Courtney B. Vance in San Diego...

Conifer Gutter Service Unveils Dependable Solutions for Year-Round Home Protection

by GlobeNewswire
May 9, 2025
0

Conifer, May 09, 2025 (GLOBE NEWSWIRE) -- Conifer, Colorado - Conifer Gutter Service is rolling out a new set of...

CSX Announces Tentative Labor Agreement with Locomotive Engineers

by GlobeNewswire
May 9, 2025
0

JACKSONVILLE, Fla., May 09, 2025 (GLOBE NEWSWIRE) -- CSX Corporation (NASDAQ: CSX) today announced it has reached a tentative agreement...

Tree Island Steel Announces First Quarter 2025 Results

by GlobeNewswire
May 9, 2025
0

VANCOUVER, British Columbia, May 09, 2025 (GLOBE NEWSWIRE) -- Tree Island Steel (''Tree Island'' or the ''Company'') (TSX: TSL) announced...

Orezone Gold Reports Fatality at Stage I Hard Rock Plant Construction Site

by GlobeNewswire
May 9, 2025
0

VANCOUVER, British Columbia, May 09, 2025 (GLOBE NEWSWIRE) -- Orezone Gold Corporation (TSX: ORE, OTCQX: ORZCF) (“Orezone”) regrets to report...

Next Post

Apellis Pharmaceuticals to Host a Fireside Chat at the Goldman Sachs 45th Annual Global Healthcare Conference

Please login to join discussion
ADVERTISEMENTS

Latest Posts

  • Montclair Pediatric Dentistry Sets a New Standard in Compassionate Pediatric Dental Care Across the Bay Area May 9, 2025
  • Boys & Girls Clubs of America Celebrates Its Esteemed Alumni Hall of Fame Class May 9, 2025
  • Conifer Gutter Service Unveils Dependable Solutions for Year-Round Home Protection May 9, 2025
  • CSX Announces Tentative Labor Agreement with Locomotive Engineers May 9, 2025
  • Tree Island Steel Announces First Quarter 2025 Results May 9, 2025
  • About Us
  • Advertise
  • Careers
  • Contact
Privacy Policy / Terms and Conditions

© 2024 ForexTV.com

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish.Accept Cookie Policy
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • News
    • Top Corporate News
    • Lifestyle
    • Technology
    • Financial Markets News
  • Small Business
    • Digital Marketing Blog
    • Small Business Best Practices
    • Small Business Strategy
      • Sales Strategies
      • Marketing Strategies
  • Business Finance
    • Small Business-Lending Trends
    • Debt Service Coverage Ratio (DSCR)
    • Business Credit
      • Business Credit Blog
      • Business Loans
      • Merchant Cash Advances
      • Business Line of Credit
      • What is Alternative Business Lending?
    • Resources
      • Debt Service Coverage Ratio (DSCR) Calculator
  • Currency Focus
    • Crypto Focus
      • Bitcoin (BTC)
      • Ethereum (ETH)
      • Tether
      • BNB
      • Cardano (Ada)
      • Ripple (XRP)
      • Solana (SOL)
      • Dogecoin (DOGE)
      • Polkadot (DOT)
      • Tron (TRX)
      • Shiba Inu (SHIB)
      • Litecoin (LTC)
    • EURO (EUR)
    • Japanese Yen (JPY)
    • Great British Pound (GBP)
    • Swiss Franc (CHF)
    • New Zealand Dollar (NZD)
    • Canadian Dollar (CAD)
    • Australian Dollar (AUD)
  • Resources
    • Economic Calendar
    • Trader Education
      • Candlestick Pattern Intro
    • Live Forex Rates/Charts
      • Live Rates
      • Live Charts
    • Forex Trader Tools
      • Pivot Point Calculator
      • Currency Converter
      • Global Statistic Resources
    • Trading Terms
      • Forex Glossary
      • Glossary of Retirement Industry Terms
    • CPI Tools
      • CPI Inflation Calculator
      • CPI Average Price Calculator
  • Marketing Services
    • Digital Marketing Services
    • Digital Marketing Consulting
    • Search Engine Optimization (SEO)
    • Online Content Marketing
    • Digital Marketing Blog
    • Inbound Marketing Services
    • Email Marketing
    • Digital Marketing Rates

© 2024 ForexTV.com