Inside Operation Diplomatic Specter: Chinese APT Group's Stealthy Tactics Exposed
ID: d9bba5be-03b7-5b06-9627-d26483ab62c5
STIX ID: report--d9bba5be-03b7-5b06-9627-d26483ab62c5
Feed Name: The Hacker News
Operation Diplomatic Specter is an ongoing Chinese-aligned APT campaign (tracked as CL-STA-0043 / TGR-STA-0043) active since at least late 2022 that conducts targeted espionage against diplomatic, governmental, and military entities in the Middle East, Africa, and Asia. The actor leverages Exchange server vulnerabilities (ProxyLogon/ProxyShell) to access mail servers, deploys Gh0st RAT-derived backdoors (TunnelSpecter and SweetSpecter), uses DNS tunneling and other stealthy exfiltration methods to steal archived inboxes and sensitive documents, and reuses infrastructure and tools associated with known China-linked groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
