Operation Crimson Palace: Sophos threat hunting unveils multiple clusters of Chinese state-sponsored activity targeting Southeast Asian government
Cosa significa
MISP EudorIA ha pubblicato l'advisory "Operation Crimson Palace: Sophos threat hunting unveils multiple clusters of Chinese state-sponsored activity targeting Southeast Asian government". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Perché conta
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Azioni consigliate
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Testo acquisito dalla fonte
Evento MISP pubblicato con TLP:CLEAR: Operation Crimson Palace: Sophos threat hunting unveils multiple clusters of Chinese state-sponsored activity targeting Southeast Asian government. Report from - [URL rimossa] (1717863357) html Google Tag Manager (noscript) End Google Tag Manager (noscript) Skip to content .entry-header In May 2023, in a threat hunt across Sophos Managed Detection and Response telemetry, Sophos MDR’s Mark Parsons uncovered a complex, long-running Chinese state-sponsored cyberespionage operation we have dubbed “Crimson Palace” targeting a high-profile government organization in Southeast Asia. MDR launched the hunt after the discovery of a DLL sideloading technique that exploited **[dominio rimosso]**, a VMware component. In the investigation that followed, we tracked at least three clusters of intrusion activity from March 2023 to December 2023. The hunt also uncovered previously unreported malware associated with the threat clusters, as well as a new, improved variant of the previously-reported EAGERBEE malware. In line with our standard internal nomenclature, Sophos tracks these clusters as Cluster Alpha (STAC1248), Cluster Bravo (STAC1807), and Cluster Charlie (STAC1305). While our visibility into the targeted network was limited due to the extent to which Sophos endpoint protection had been deployed within the organization, our investigations also found evidence of related earlier intrusion activity dating back to early 2022. This led us to suspect the threat actors had long-standing access to unmanaged assets within the network. The c
- Fonte
- MISP EudorIA
- Entità pubblicatrice
- MISP EudorIA
- Tipo entità
- Comunità di intelligence
- Area
- Global
- Lingua originale
- it · traduzione non necessaria
- Pubblicazione
- 30/07/2026 02:51
- Condivisione
- TLP:CLEAR
- Indicatori dichiarati dalla fonte
- 127
- IOC indicizzati per la ricerca
- 0 valori nel periodo di conservazione
- IOC disponibili nel feed STIX
- 127Ultima verifica di condivisione: 2026-09-26T03:04:07.881848+00:00
- Evento MISP
- f48f7c30-fe6f-4854-b27e-f86a308da714
- Classificazione
- Media