logo

China-Backed APT Group Culling Thai Government Data

ID: 6906b0c7-bfab-5657-9290-3b088de17daf

STIX ID: report--6906b0c7-bfab-5657-9290-3b088de17daf

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-10-03

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

ESET researchers attribute a sustained, China-aligned APT campaign named CeranaKeeper (active since early 2022) to widespread data-harvesting operations across Southeast Asia; the group used brute-force access to a Thai government domain controller, deployed the Toneshell backdoor and credential-dumping tools, abused a legitimate Avast driver to disable protections, and adapted both Mustang Panda components and new tooling to exfiltrate large volumes of files and undermine common file-sharing services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.