CL-UNK-1068: The Stealthy Chinese Threat Actor Haunting Asian Infrastructure
ID: d0085452-e8f4-52a4-8394-84b28e5b0edc
STIX ID: report--d0085452-e8f4-52a4-8394-84b28e5b0edc
Feed Name: securityonline.info
Unit 42 describes CL-UNK-1068, a suspected Chinese APT active since 2020 that targets critical sectors across Asia using cross-platform tools (custom malware, modified open-source utilities, LOLBINs). The report details initial access via GodZilla/AntSword web shells, lateral movement to SQL servers, credential theft (Mimikatz, Dumpit, Volatility, SSMS password tools), a stealthy Base64 exfiltration technique using certutil and web shells, and unique reconnaissance artifacts (SuperDump, hp.bat/hpp.bat).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
