Hackers Target Asian Critical Infrastructure Using Web Server Exploits and Mimikatz
Mar 9, 2026 // 12:35 - Norina Velotta


Researchers identified a Chinese threat actor, CL-UNK-1068, conducting a multi-year campaign against critical infrastructure in South, Southeast, and East Asia. These attacks target high-stakes sectors like aviation, energy, telecommunications, and government.

Attack Vector: Web Server Exploitation

The campaign typically starts by hitting public-facing web servers to gain a foothold.

  • Web Shells: Attackers use Chinese-language tools like GodZilla and AntSword to maintain control over compromised servers.
  • SharePoint & SAP: Recent activity has focused on on-premises SharePoint vulnerabilities and unauthenticated file upload flaws in SAP NetWeaver Visual Composer.

Credential Theft: Mimikatz & Tooling

Once inside, the actors focus on harvesting credentials to move deeper into the network:

  • Mimikatz: This is the primary tool used to dump plaintext passwords and NTLM hashes from memory.
  • Custom Variants: Attackers often use modified versions like mimCN (used in Operation Digital Eye) for “pass-the-hash” attacks.
  • Specialized Stealers: They utilize tools like LsaRecorder to capture WinLogon passwords in real-time and specific scripts to extract SQL Server Management Studio credentials.

Persistence & Movement

To stay hidden, the group uses “living-off-the-land” techniques:

  • DLL Side-Loading: They often use legitimate Python executables to side-load malicious files.
  • Internal Scanning: Tools like FScan and Fast Reverse Proxy (FRP) are used to map out the internal network once the initial server is breached.

#and  #asian  #critical  #exploits  #hackers  #infrastructure  #mimikatz  #news  #server  #target  #using  #web   —   News