216.73.216.6

Weaver Ant, the Web Shell Whisperer: Tracking a China-Nexus Cyber Operation

· Published 25/03/2025 13:10 · Modified 25/03/2025 13:20

Export JSON

Essential information

Published
25/03/2025 13:10
Modified
25/03/2025 13:20
Tags
2025-03-25 china chopper china-nexus espionage evasion inmemory web shell lateral movement persistence telecom tunneling web shells
Related entities
1 observables, 1 intrusion sets (apt), 26 techniques (mitre), 2 malware, 1 others

Description

Sygnia uncovered a sophisticated threat actor, Weaver Ant, targeting a major Asian company. The group employed and techniques for and , maintaining access for over four years. They utilized encrypted and custom 'INMemory' , along with a recursive HTTP tunnel tool for internal network access. Weaver Ant demonstrated advanced techniques, including ETW patching, AMSI bypassing, and 'PowerShell without PowerShell' execution. The operation involved extensive reconnaissance, credential harvesting, and data exfiltration. Despite eradication attempts, the group showed remarkable , adapting their tactics to regain access.

External references