Separating the bee from the panda: CeranaKeeper making a beeline for Thailand
ID: 4326fb7d-34ab-5b87-8cc8-716e121b278e
STIX ID: report--4326fb7d-34ab-5b87-8cc8-716e121b278e
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET identifies CeranaKeeper, a China-aligned APT that has targeted governmental organizations across Asia since at least 2022; the group employs revamped TONESHELL components and bespoke tools (WavyExfiller, DropboxFlop, OneDoor, BingoShell) that abuse Pastebin, Dropbox, OneDrive, GitHub and other services for stealthy command-and-control and large-scale document exfiltration, and the report provides technical analysis, IoCs, hosting details, and ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
