IcePeony with the ‘996’ work culture
ID: 1edbf5d4-c54b-593a-a733-a7f97b03277e
STIX ID: report--1edbf5d4-c54b-593a-a733-a7f97b03277e
Feed Name: Nao_Sec
**IcePeony** is a newly identified China‑nexus APT active since at least 2023 targeting government, academic, and political entities in India, Vietnam, Mauritius (and possibly Brazil), with campaigns that begin via SQL injection and proceed to webshell/backdoor deployment, credential theft, and lateral movement; analysis of an exposed attacker server and zsh_history reveals a two‑week workflow leveraging custom tools (StaX), open‑source utilities (sqlmap, ProxyChains), a rootkit (Diamorphine), and bespoke IIS malware (IceCache) plus a passive backdoor (IceEvent) sharing code/PDB links, while work patterns and Simplified Chinese artifacts support attribution, and the report provides detailed IoCs (IPs, domains, and hashes) and malware command capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
