logo

Separating the bee from the panda: CeranaKeeper making a beeline for Thailand

ID: 4326fb7d-34ab-5b87-8cc8-716e121b278e

STIX ID: report--4326fb7d-34ab-5b87-8cc8-716e121b278e

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2024-10-02

Date Updated: 2026-05-01

...
...

ESET identifies CeranaKeeper, a China-aligned APT that has targeted governmental organizations across Asia since at least 2022; the group employs revamped TONESHELL components and bespoke tools (WavyExfiller, DropboxFlop, OneDoor, BingoShell) that abuse Pastebin, Dropbox, OneDrive, GitHub and other services for stealthy command-and-control and large-scale document exfiltration, and the report provides technical analysis, IoCs, hosting details, and ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.