Operation Sea Elephant: The Dying Walrus Wandering the Indian Ocean
Essential information
- Published
- 10/04/2025 18:50
- Modified
- 10/04/2025 20:12
- Tags
- 2025-04-10 aliyun_updater64.exe cachestore.exe file stealing filecoauthx86.exe github api huaweihisuiteservice64.exe keylogging konlinesetupupdate_xa.exe mscleanup64.exe ocean research qaxreporter.exe scientific espionage sogou_pinyinupdater.exe south asia srclogsys.exe steganography tericerit.exe usb propagation windowassistance.exe windowsfilters.exe youdaogui.exe
- Related entities
- 1 intrusion sets (apt), 15 techniques (mitre), 13 malware, 4 others
Description
The CNC group, with South Asian origins, has been targeting domestic teachers, students, and research institutions. Their operation, named 'sea elephant', aims to spy on scientific research achievements in the ocean field. The group employs various tactics, including spear-phishing emails, IM software exploitation, and customized plug-ins. Their malware includes remote command execution backdoors, USB flash drive propagation tools, keyloggers, and file stealers. The attackers use GitHub APIs and steganographic techniques to avoid detection. The operation's focus on ocean-related research suggests a nation's determination to dominate the Indian Ocean region. Additionally, a related campaign, UTG-Q-011, targets areas such as laser science and aerospace.