GroundPeony: Crawling with Malice
ID: e740d9b2-2edf-5709-aa38-ce753baa676d
STIX ID: report--e740d9b2-2edf-5709-aa38-ce753baa676d
Feed Name: Nao_Sec
This report analyzes GroundPeony (aka UNC3347), a China‑nexus APT active since at least 2021, which targeted Taiwanese and Nepalese government organizations via spear‑phishing and compromised websites using obfuscated URLs, multi‑stage loaders (mic.exe/version.dll), DLL sideloading, and a custom downloader (“micDown”) to retrieve shellcode/Cobalt Strike from C2 such as app.onedrivo.com and 103.199.17.184. It highlights the group’s early exploitation of CVE‑2022‑30190 (Follina) as a zero‑day, traces related campaigns, and provides actionable IoCs, infrastructure details, and TTPs to aid SOC/IR defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
