Operation DRAGONCLONE: Chinese Telecom Targeted by Malware
Essential information
- Published
- 07/06/2025 10:12
- Modified
- 09/06/2025 10:09
- Tags
- 2025-06-06 2025-06-07 CVE-2024-1709 CVE-2025-31324 asset lighthouse system callback-execution china-nexus cobalt strike dll sideloading earth lamia ipfuscation supershell unc5174 veletrix vshell
- Related entities
- 1 intrusion sets (apt), 13 techniques (mitre), 4 malware, 2 others
Description
A sophisticated campaign targeting China Mobile Tietong Co., Ltd., a subsidiary of China Mobile, has been uncovered. The attack employs VELETRIX, a new loader, and VShell, a known adversary simulation tool. The infection chain begins with a malicious ZIP file containing executable and DLL files. VELETRIX uses anti-analysis techniques, IPFuscation, and a callback mechanism to execute VShell. The campaign shows overlaps with UNC5174 (Uteus) and Earth Lamia, known China-nexus threat actors. The infrastructure utilizes tools like SuperShell, Cobalt Strike, and Asset Lighthouse System. Active since March 2025, this operation demonstrates advanced tactics, techniques, and procedures associated with Chinese state-sponsored threat groups.