Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia
ID: cbbc1751-9b2b-5053-8490-fa9c6b627924
STIX ID: report--cbbc1751-9b2b-5053-8490-fa9c6b627924
Feed Name: Palo Alto Networks Unit 42
**Executive Summary:** Unit 42 documents Operation Diplomatic Specter, a high-confidence Chinese state-aligned espionage campaign active since late 2022 that compromises Exchange and web servers (leveraging ProxyLogon/ProxyShell) to exfiltrate diplomatic, military, and governmental email data across the Middle East, Africa, and Asia using custom backdoors (TunnelSpecter, SweetSpecter), Gh0st RAT variants, DNS tunneling and other stealthy TTPs; the report provides technical analysis, IoCs (hashes, domains, IPs), infrastructure overlaps, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
