logo

Chinese hacking groups team up in cyber espionage campaign

ID: 79948cc4-b228-563f-b7fb-d6ef9624b102

STIX ID: report--79948cc4-b228-563f-b7fb-d6ef9624b102

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-06-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Crimson Palace is a multi‑cluster Chinese state‑sponsored cyberespionage campaign targeting a Southeast Asian government agency since at least March 2022/2023; Sophos observed three coordinated clusters (Alpha, Bravo, Charlie) using custom backdoors (EAGERBEE, CCoreDoor, PocoProxy, Nupakage), DLL side‑loading, LOLBins, credential dumping, and persistent C2 to conduct AD reconnaissance, credential theft, lateral movement and long‑term access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.