Weaver Ant data exfiltration campaign (Campaign)
ID: 7dad4e94-1a1e-5d74-9fdb-69be0bde67dc
STIX ID: report--7dad4e94-1a1e-5d74-9fdb-69be0bde67dc
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-03-24
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Sygnia tracked a long-running China-nexus APT campaign dubbed Weaver Ant that maintained covert access to a major Asian telecom for over four years using advanced web shells (including an AES-encrypted China Chopper and an INMemory web shell), trojanized DLLs, credential theft, recursive HTTP tunneling, AMSI/ETW evasion, and in-memory execution to perform reconnaissance, lateral movement, and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
