China APT Stole Geopolitical Secrets From Middle East, Africa & Asia
ID: 9e1ae320-9387-5857-aace-dd9e3415a7d5
STIX ID: report--9e1ae320-9387-5857-aace-dd9e3415a7d5
Feed Name: Dark Reading
Operation Diplomatic Specter is an ongoing Chinese state-aligned espionage campaign (since late 2022) that daily exfiltrates emails and files from high-value targets — foreign ministries, militaries, embassies and related organizations across the Middle East, Africa, and Southeast Asia — by exploiting internet-facing Web and Microsoft Exchange servers (ProxyLogon, ProxyShell) and deploying in-memory VBScript implants and a toolkit including Gh0st RAT, PlugX, SweetSpecter and TunnelSpecter; defenders are urged to prioritize patching, network monitoring, detection and defense-in-depth.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
