Unfading Sea Haze: New Espionage Campaign in the South China Sea
ID: 18b3695e-5f50-569a-a44c-319b0f7eca1a
STIX ID: report--18b3695e-5f50-569a-a44c-319b0f7eca1a
Feed Name: Bitdefender Labs
Bitdefender documents an espionage campaign by the Unfading Sea Haze APT, active since at least 2018, that targeted at least eight military and government organizations in the South China Sea region. The actor uses spearphishing (ZIP archives with LNK), multiple backdoors and Gh0stRat variants, and legitimate RMM tools to maintain access and exfiltrate documents, browser data, and messaging files; the whitepaper and Bitdefender intelligence portal provide IOCs and deeper analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
