Weaver Ant, the Web Shell Whisperer: Tracking a China-Nexus Cyber Operation
Essential information
- Published
- 25/03/2025 13:10
- Modified
- 25/03/2025 13:20
- Tags
- 2025-03-25 china chopper china-nexus espionage evasion inmemory web shell lateral movement persistence telecom tunneling web shells
- Related entities
- 1 observables, 1 intrusion sets (apt), 26 techniques (mitre), 2 malware, 1 others
Description
Sygnia uncovered a sophisticated China-nexus threat actor, Weaver Ant, targeting a major Asian telecom company. The group employed web shells and tunneling techniques for persistence and lateral movement, maintaining access for over four years. They utilized encrypted China Chopper and custom 'INMemory' web shells, along with a recursive HTTP tunnel tool for internal network access. Weaver Ant demonstrated advanced evasion techniques, including ETW patching, AMSI bypassing, and 'PowerShell without PowerShell' execution. The operation involved extensive reconnaissance, credential harvesting, and data exfiltration. Despite eradication attempts, the group showed remarkable persistence, adapting their tactics to regain access.