logo

Inside Operation Diplomatic Specter: Chinese APT Group's Stealthy Tactics Exposed

ID: d9bba5be-03b7-5b06-9627-d26483ab62c5

STIX ID: report--d9bba5be-03b7-5b06-9627-d26483ab62c5

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-05-23

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Operation Diplomatic Specter is an ongoing Chinese-aligned APT campaign (tracked as CL-STA-0043 / TGR-STA-0043) active since at least late 2022 that conducts targeted espionage against diplomatic, governmental, and military entities in the Middle East, Africa, and Asia. The actor leverages Exchange server vulnerabilities (ProxyLogon/ProxyShell) to access mail servers, deploys Gh0st RAT-derived backdoors (TunnelSpecter and SweetSpecter), uses DNS tunneling and other stealthy exfiltration methods to steal archived inboxes and sensitive documents, and reuses infrastructure and tools associated with known China-linked groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.