logo

China APT Stole Geopolitical Secrets From Middle East, Africa & Asia

ID: 9e1ae320-9387-5857-aace-dd9e3415a7d5

STIX ID: report--9e1ae320-9387-5857-aace-dd9e3415a7d5

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-05-23

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

Operation Diplomatic Specter is an ongoing Chinese state-aligned espionage campaign (since late 2022) that daily exfiltrates emails and files from high-value targets — foreign ministries, militaries, embassies and related organizations across the Middle East, Africa, and Southeast Asia — by exploiting internet-facing Web and Microsoft Exchange servers (ProxyLogon, ProxyShell) and deploying in-memory VBScript implants and a toolkit including Gh0st RAT, PlugX, SweetSpecter and TunnelSpecter; defenders are urged to prioritize patching, network monitoring, detection and defense-in-depth.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.