216.73.216.6

Operation DRAGONCLONE: Chinese Telecom Targeted by Malware

· Published 07/06/2025 10:12 · Modified 09/06/2025 10:09

Export JSON

Essential information

Published
07/06/2025 10:12
Modified
09/06/2025 10:09
Tags
2025-06-06 2025-06-07 CVE-2024-1709 CVE-2025-31324 asset lighthouse system callback-execution china-nexus cobalt strike dll sideloading earth lamia ipfuscation supershell unc5174 veletrix vshell
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 4 malware, 2 others

Description

A sophisticated campaign targeting China Mobile Tietong Co., Ltd., a subsidiary of China Mobile, has been uncovered. The attack employs , a new loader, and , a known adversary simulation tool. The infection chain begins with a malicious ZIP file containing executable and DLL files. uses anti-analysis techniques, , and a callback mechanism to execute . The campaign shows overlaps with (Uteus) and , known threat actors. The infrastructure utilizes tools like , , and . Active since March 2025, this operation demonstrates advanced tactics, techniques, and procedures associated with Chinese state-sponsored threat groups.

External references