惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
罗磊的独立博客
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
D
Docker
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
月光博客
月光博客
S
SegmentFault 最新的问题
Jina AI
Jina AI
Blog — PlanetScale
Blog — PlanetScale
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - Franky
L
LangChain Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Microsoft Azure Blog
Microsoft Azure Blog
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Last Week in AI
Last Week in AI

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
DeadRinger Operation
Intel 471 · 2021-11-16 · via Intel 471 Blog

DeadRinger Summary

The DeadRinger operation was comprised of three campaigns led by different threat groups linked to China, targeting major Telecommunications Companies in Southeast Asia. The groups consisted of SoftCell, Naikon APT and Group-3390, which are attributed with operating for Chinese state interests. When the campaigns were discovered, researchers were able to link malicious activity dating as far back as 2017 until the present day. This activity consisted of exploits of Microsoft Exchange vulnerabilities (unknown at the time) and various forms of backdoors that helped the actors maintain persistence in the victim's environments.

TTPs observed in these campaigns were similar to tactics utilized in the Hafnium zero-day attacks, which were attributed to China by the White House in March of 2021. The resemblances with the DeadRinger operation can be found in the techniques used, but the exploitation of Microsoft Exchange vulnerabilities are most interesting. Although all three campaigns (or clusters) are executed by different groups, their tactics, techniques, and victims (sometimes seen on the same endpoints at the same time!) overlap and potentially show a parallel in objectives via high value targets within the Telecommunications industry.

DeadRinger Synopsis

In August 2021, it was discovered there were three malicious campaigns targeting major
Southeast Asian telecommunications companies - since as far back as in 2017. The three threat
groups were known to have Chinese state affiliation (Soft Cell, Naikon, and Group-3390), along
with the same target and similar techniques. These techniques allowed them to achieve and
maintain persistence on infected machines and environments. The observed operations utilized
methods such as (but not limited to): exploitation of Microsoft Exchange Server vulnerabilities,
China Chopper web shell, Cobalt Strike beacons, a modified Mimikatz tool and various
backdoors utilized for data exfiltration. CyberReason's report divided the campaigns into
clusters, each designated and identified by threat actor.

Cluster A

Cluster A was affiliated with Soft Cell, a cyber espionage group who have been observed in
operation since 2010. They abused Microsoft Exchange vulnerabilities in order to gain access
throughout, and installed China Chopper WebShell to perform commands. During this cluster:
the actor was seen utilizing the "$RECYCLE.BIN" folder for obfuscation, then utilized Windows
Native tools for Reconnaissance purposes (whoami, ping, etc). Batch scripts were also observed
to be used for environment reconnaissance and preparation for exfiltration. For lateral
movement, Soft Cell used WMI and Net Use to establish network connections used to traverse
the environment. Note: actors hid contents of stolen data within a ".RAR" file stashed in the
"C:\users\SUPPORT_388945a0\Documents" path - which was then exfiltrated via China
Chopper web shell. The actors also utilized PcShare as a backdoor, side-loading the loader
legitimate "nvSmarEx.exe" executable - as well as SoftEther VPN for persistence and access
purposes. Changes in TTPs were also observed throughout each phase, such as introducing new
tools for Reconnaissance (like Local group or NBTScan).

Cluster B

Cluster B was affiliated with Naikon, observed to be in operation since 2020. The Naikon APT
group was "previously attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu
Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator
78020)." Their initial vector of compromising is not known, however their TTPs were different
than those observed in Cluster A. For example the usage of the Nebulae backdoor (executed via
DLL side-loading trusted apps, like chrome_frame_helper.exe), which enabled a wealth of
accessibility for the attacker - such as Reconnaissance, File/Process manipulation, Command
execution, Privilege Escalation, and C2 communications. When stealing credentials, Naikon used
ProcDump and a modified Mimikatz tool for extraction, as well as "EnrollLogger" keylogger.

Cluster C

Cluster C was affiliated with Group-3390 (or Emissary Panda), observed activity from 2017 to 2021. Similar to Cluster A, Group-3390 utilized Microsoft Exchange server vulnerabilities
(unknown at the time) in order to gain initial access. They are unique with the deployment of a
"Outlook Web Access backdoor" (Microsoft.Exchange.Clients.Event.dll) that was seen across
Exchange and IIS servers. It would intercept any requests that contained "owa/auth.owa" and
logs the data. This data could include IP Addresses and Credentials. It is then hidden with an
XOR cipher and exfiltrated/deleted when the attacker connects with a unique session ID. This
method has been recently exploited during the HAFNIUM attacks in March 2021.

Get the Free Hunt Packages!

Check Out Other Emerging Threats >