logo

Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia

ID: cbbc1751-9b2b-5053-8490-fa9c6b627924

STIX ID: report--cbbc1751-9b2b-5053-8490-fa9c6b627924

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2024-05-23

Date Updated: 2026-04-28

Author: Lior Rochberger and Daniel Frank

...
...

**Executive Summary:** Unit 42 documents Operation Diplomatic Specter, a high-confidence Chinese state-aligned espionage campaign active since late 2022 that compromises Exchange and web servers (leveraging ProxyLogon/ProxyShell) to exfiltrate diplomatic, military, and governmental email data across the Middle East, Africa, and Asia using custom backdoors (TunnelSpecter, SweetSpecter), Gh0st RAT variants, DNS tunneling and other stealthy TTPs; the report provides technical analysis, IoCs (hashes, domains, IPs), infrastructure overlaps, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.