logo

China-Nexus APT 'Weaver Ant' Caught in Yearslong Web Shell Attack

ID: 625f0832-d945-5edd-8ee0-d90f07df6110

STIX ID: report--625f0832-d945-5edd-8ee0-d90f07df6110

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-03-24

Date Updated: 2026-04-21

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

Sygnia reported on "Weaver Ant," a China-linked APT that maintained long-term access to a major Asian telecom by deploying web shells (China Chopper and an "INMemory" variant) to execute in-memory payloads, establish recursive HTTP tunneling between web shells for lateral movement, and conceal multi-layered malicious payloads; investigators observed years-long compromise, uncovered dozens of web shells and provided technical details, IOCs, and defensive/hunting recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.