China-Backed APT Group Culling Thai Government Data
ID: 6906b0c7-bfab-5657-9290-3b088de17daf
STIX ID: report--6906b0c7-bfab-5657-9290-3b088de17daf
Feed Name: Dark Reading
ESET researchers attribute a sustained, China-aligned APT campaign named CeranaKeeper (active since early 2022) to widespread data-harvesting operations across Southeast Asia; the group used brute-force access to a Thai government domain controller, deployed the Toneshell backdoor and credential-dumping tools, abused a legitimate Avast driver to disable protections, and adapted both Mustang Panda components and new tooling to exfiltrate large volumes of files and undermine common file-sharing services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
