logo

GroundPeony: Crawling with Malice

ID: e740d9b2-2edf-5709-aa38-ce753baa676d

STIX ID: report--e740d9b2-2edf-5709-aa38-ce753baa676d

Feed Name: Nao_Sec

Threat Score

Date Published: 2023-08-22

Date Updated: 2026-03-24

Author: nao_sec

...
...

This report analyzes GroundPeony (aka UNC3347), a China‑nexus APT active since at least 2021, which targeted Taiwanese and Nepalese government organizations via spear‑phishing and compromised websites using obfuscated URLs, multi‑stage loaders (mic.exe/version.dll), DLL sideloading, and a custom downloader (“micDown”) to retrieve shellcode/Cobalt Strike from C2 such as app.onedrivo.com and 103.199.17.184. It highlights the group’s early exploitation of CVE‑2022‑30190 (Follina) as a zero‑day, traces related campaigns, and provides actionable IoCs, infrastructure details, and TTPs to aid SOC/IR defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.