Chinese hacking groups team up in cyber espionage campaign
ID: 79948cc4-b228-563f-b7fb-d6ef9624b102
STIX ID: report--79948cc4-b228-563f-b7fb-d6ef9624b102
Feed Name: Bleeping Computer
Threat Score
Crimson Palace is a multi‑cluster Chinese state‑sponsored cyberespionage campaign targeting a Southeast Asian government agency since at least March 2022/2023; Sophos observed three coordinated clusters (Alpha, Bravo, Charlie) using custom backdoors (EAGERBEE, CCoreDoor, PocoProxy, Nupakage), DLL side‑loading, LOLBins, credential dumping, and persistent C2 to conduct AD reconnaissance, credential theft, lateral movement and long‑term access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
