Chinese Tag Team APTs Keep Stealing Asian Gov't Secrets
ID: 9f503e3f-529a-583f-b354-5ab768e04633
STIX ID: report--9f503e3f-529a-583f-b354-5ab768e04633
Feed Name: Dark Reading
Threat Score
Operation Crimson Palace is a China-linked, multi-cluster APT campaign active since March 2023 and increasingly active in 2024; Sophos attributes at least a dozen compromises (including a prominent Southeast Asian government agency) to three specialized clusters where Alpha handles initial access, Bravo manages infrastructure and C2 relays, and Charlie performs sophisticated persistence, evasion, and data exfiltration using a combination of custom tooling and open-source frameworks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
