China-Nexus APT 'Weaver Ant' Caught in Yearslong Web Shell Attack
ID: 625f0832-d945-5edd-8ee0-d90f07df6110
STIX ID: report--625f0832-d945-5edd-8ee0-d90f07df6110
Feed Name: Dark Reading
Date Published: 2025-03-24
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
Sygnia reported on "Weaver Ant," a China-linked APT that maintained long-term access to a major Asian telecom by deploying web shells (China Chopper and an "INMemory" variant) to execute in-memory payloads, establish recursive HTTP tunneling between web shells for lateral movement, and conceal multi-layered malicious payloads; investigators observed years-long compromise, uncovered dozens of web shells and provided technical details, IOCs, and defensive/hunting recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
