logo

Cyber Espionage Group CL-UNK-1068 Linked to China Targets Asian Infrastructure

ID: b3af567c-03da-59e9-8d52-a98d584afc2f

STIX ID: report--b3af567c-03da-59e9-8d52-a98d584afc2f

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Divya

...
...

CL-UNK-1068 is described as a highly sophisticated, China-origin cyber espionage group active since at least 2020 targeting aviation, energy, government, law enforcement, technology, and telecommunications across South, Southeast, and East Asia; they use web shells (GodZilla/AntSword), DLL side-loading of Python binaries, custom Go-based scanners (ScanPortPlus), a modified FRP tunnel with token 'frpforzhangwei', Xnote Linux backdoors, and credential-theft and exfiltration techniques to maintain persistence and siphon sensitive data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.