Emerging Threats to Remote Access VPNs
Chinese state-sponsored hackers have been targeting a government agency in Southeast Asia since March 2023 in a sophisticated cyber espionage campaign known as Crimson Palace. The campaign involved new malware variants and three distinct activity clusters, suggesting a coordinated effort among various Chinese hacking groups.
Discovery and Nature of the Attack
The Crimson Palace campaign revealed that attackers had been using custom Nupakage malware, previously linked to the Chinese threat group Mustang Panda. The initial access point remains unclear, but related activities date back to early 2022.
Activity Clusters
Three distinct activity clusters in the campaign were associated with known Chinese threat groups such as BackdoorDiplomacy, REF5961, Worok, TA428, and the APT41 subgroup Earth Longzhi. These clusters are believed to have operated under a single organization.
Cluster Alpha (STAC1248):
Active from early March to August 2023, this cluster focused on deploying updated ‘EAGERBEE’ malware variants. The primary objective was to map server subnets and enumerate administrator accounts by conducting reconnaissance on Active Directory infrastructure. The activity used multiple persistent command and control (C2) channels, including Merlin Agent, PhantomNet backdoor, RUDEBIRD malware, and PowHeartBeat backdoor. To avoid detection, the attackers employed living-off-the-land binaries (LOLBins) and DLL side-loading with eight unique DLLs.
Cluster Bravo (STAC1807):
This cluster was active for only three weeks in March 2023, focusing on lateral movement and persistence. The attackers deployed a previously unknown backdoor called ‘CCoreDoor’ to establish external C2 communications, perform discovery, and dump credentials. They used renamed versions of signed side-loadable binaries to obfuscate the backdoor deployment and facilitate lateral movement, while also overwriting ntdll.dll in memory to unhook the endpoint protection agent process from the kernel.
Cluster Charlie (SCAT1305):
Active from March 2023 to at least April 2024, this cluster was involved in persistent access management and extensive reconnaissance. The attackers deployed multiple samples of an unidentified malware called ‘PocoProxy’ for persistent C2 communications. They also used the HUI loader to inject a Cobalt Strike Beacon into mstsc.exe, though these attempts were blocked. Additionally, they injected an LSASS login credential interceptor to capture credentials on domain controllers and conducted a mass analysis of Event Logs and automated ping sweeps to map users and endpoints across the network.
High-Level Coordination
These clusters operated during standard Chinese work hours (08:00 AM to 05:00 PM CST), indicating a high level of coordination. Activity spikes were observed on dates like June 12, 2023, a holiday in the target country, likely to catch defenders understaffed.
Attribution and Persistence
Although confirming high-confidence attribution is challenging, researchers believe the detected activity represents coordinated efforts by separate actors under a central authority pursuing Chinese state interests. Blocking the threat actor’s C2 implants in August 2023 halted Cluster Alpha activity. However, Cluster Charlie activity resumed after a brief silence, with adversaries attempting to breach the network again, this time with higher intensity and evasion tactics.
Continuous Monitoring and Defense
Continuous monitoring and robust cybersecurity measures are essential to defend against such coordinated cyber espionage campaigns. The use of multiple clusters and advanced malware variants highlights the evolving nature of cyber threats and the need for comprehensive security strategies.
Conclusion
The Crimson Palace campaign underscores the sophisticated and coordinated nature of cyber espionage efforts by state-sponsored actors. Organizations must remain vigilant and adopt advanced cybersecurity measures to protect their networks from such threats. Continuous monitoring, timely patching, and multi-layered defense mechanisms are crucial in mitigating the risks posed by these advanced persistent threats.
By understanding the tactics and techniques employed in this campaign, cybersecurity professionals can better prepare and defend against similar threats in the future. The collaboration and information sharing among cybersecurity researchers and organizations are vital in combating the ever-evolving landscape of cyber espionage.

Discover more from Open Security Labs
Subscribe to get the latest posts sent to your email.







