Researchers identified a Chinese threat actor, CL-UNK-1068, conducting a multi-year campaign against critical infrastructure in South, Southeast, and East Asia. These attacks target high-stakes sectors like aviation, energy, telecommunications, and government.
Attack Vector: Web Server Exploitation
The campaign typically starts by hitting public-facing web servers to gain a foothold.
- Web Shells: Attackers use Chinese-language tools like GodZilla and AntSword to maintain control over compromised servers.
- SharePoint & SAP: Recent activity has focused on on-premises SharePoint vulnerabilities and unauthenticated file upload flaws in SAP NetWeaver Visual Composer.
Credential Theft: Mimikatz & Tooling
Once inside, the actors focus on harvesting credentials to move deeper into the network:
- Mimikatz: This is the primary tool used to dump plaintext passwords and NTLM hashes from memory.
- Custom Variants: Attackers often use modified versions like mimCN (used in Operation Digital Eye) for “pass-the-hash” attacks.
- Specialized Stealers: They utilize tools like LsaRecorder to capture WinLogon passwords in real-time and specific scripts to extract SQL Server Management Studio credentials.
Persistence & Movement
To stay hidden, the group uses “living-off-the-land” techniques:
- DLL Side-Loading: They often use legitimate Python executables to side-load malicious files.
- Internal Scanning: Tools like FScan and Fast Reverse Proxy (FRP) are used to map out the internal network once the initial server is breached.