216.73.216.6

Operation Sea Elephant: The Dying Walrus Wandering the Indian Ocean

· Published 10/04/2025 18:50 · Modified 10/04/2025 20:12

Export JSON

Essential information

Published
10/04/2025 18:50
Modified
10/04/2025 20:12
Tags
2025-04-10 aliyun_updater64.exe cachestore.exe file stealing filecoauthx86.exe github api huaweihisuiteservice64.exe keylogging konlinesetupupdate_xa.exe mscleanup64.exe ocean research qaxreporter.exe scientific espionage sogou_pinyinupdater.exe south asia srclogsys.exe steganography tericerit.exe usb propagation windowassistance.exe windowsfilters.exe youdaogui.exe
Related entities
1 intrusion sets (apt), 15 techniques (mitre), 13 malware, 4 others

Description

The CNC group, with South Asian origins, has been targeting domestic teachers, students, and research institutions. Their operation, named 'sea elephant', aims to spy on scientific research achievements in the ocean field. The group employs various tactics, including spear-phishing emails, IM software exploitation, and customized plug-ins. Their malware includes remote command execution backdoors, USB flash drive propagation tools, keyloggers, and file stealers. The attackers use GitHub APIs and steganographic techniques to avoid detection. The operation's focus on ocean-related research suggests a nation's determination to dominate the Indian Ocean region. Additionally, a related campaign, UTG-Q-011, targets areas such as laser science and aerospace.

External references