1
00:00:04,120 --> 00:00:11,320
Welcome to Spycraft, a podcast that
tells gripping life and death spy stories and

2
00:00:11,439 --> 00:00:17,160
the amazing devices and operations that made
them possible. Now let's get started.

3
00:00:23,199 --> 00:00:28,480
Sooks Sophos, a global leader of
innovative security solutions for defeating cyber attacks,

4
00:00:28,480 --> 00:00:34,960
released a report Operation Crimson Palace threat
in Hunting. Threat Hunting unveils multiple clusters

5
00:00:35,000 --> 00:00:41,600
of Chinese sponsored activity targeting Southeast Asia. Sofolks ex Ops finds links between five

6
00:00:41,640 --> 00:00:46,079
well known Chinese threat groups, including
APT four to one and Backdoor Diplomacy.

7
00:00:46,799 --> 00:00:55,359
Chinese attackers leverage previously unseen malware for
espionage and persistence. The Operation Crimson Palace

8
00:00:55,399 --> 00:00:59,640
details a highly sophisticated, nearly two
year long espionage campaign against a high level

9
00:00:59,640 --> 00:01:03,760
government target. During sofos exops investigation, which began in two twenty twenty three,

10
00:01:04,159 --> 00:01:08,799
they managed detection and response team found
three distinct clusters of activity targeting the

11
00:01:08,840 --> 00:01:14,439
same organization, two of which included
tactics, techniques, and procedures that overlap

12
00:01:14,519 --> 00:01:19,799
with well known Chinese nation state groups
Backdoor Diplomacy, APT one five and the

13
00:01:19,840 --> 00:01:25,799
APTE forty one subgroup earth Longzi.
The attackers designed their operation to gather reconnaissance

14
00:01:25,879 --> 00:01:29,599
on specific users, as well as
sensitive political, economic, and military information,

15
00:01:29,799 --> 00:01:33,640
using a wide variety of malware and
tools throughout the campaign that SOFOS has

16
00:01:33,640 --> 00:01:40,480
since dubbed Crimson Palace. This includes
previously unseen malware a persistence tool that SOFOS

17
00:01:40,560 --> 00:01:44,799
named Poco Proxy. The different clusters
appeared to have been working in support of

18
00:01:44,879 --> 00:01:49,480
Chinese state interests by gathering military and
economic intelligence related to the country's strategies in

19
00:01:49,519 --> 00:01:53,680
the South China Sea in this particular
campaign. They believe these three clusters represented

20
00:01:53,719 --> 00:01:57,319
distinct groups of attackers who are working
in parallel against the same target under the

21
00:01:57,359 --> 00:02:02,400
overarching directive of a central state authority. Within just one of the three clusters

22
00:02:02,400 --> 00:02:07,359
that they identified, Cluster Alpha,
they saw malware and TTP's overlap with four

23
00:02:07,400 --> 00:02:13,000
separately reported Chinese threat groups. It's
well known the Chinese attackers share infrastructure and

24
00:02:13,719 --> 00:02:16,800
tooling. In this recent campaign's a
reminder of just how extensively these groups share

25
00:02:16,800 --> 00:02:22,120
their tools and techniques. As Western
governments elevate awareness about cyber threats from China,

26
00:02:22,159 --> 00:02:25,000
the overlap SOFOS is uncovered as an
important reminder they're focusing too much on

27
00:02:25,120 --> 00:02:30,719
any single Chinese attribution. We put
organizations at risk of missing trends about how

28
00:02:30,759 --> 00:02:37,039
these groups coordinate their operations. By
having a bigger, broader picture, organizations

29
00:02:37,080 --> 00:02:43,000
can be smarter about their defenses.
There were three clusters they found. Cluster

30
00:02:43,520 --> 00:02:47,479
Alpha, Cluster Bravo, and Cluster
Charlie were the ones associated with this espionage

31
00:02:47,599 --> 00:02:55,479
attack over in Southeast Asia. They
didn't specify what countries were being hit or

32
00:02:55,520 --> 00:03:00,719
anything of that sort. Well,
actually, we'll look at Operation Crimson.

33
00:03:00,960 --> 00:03:05,319
In May of twenty twenty three,
it was a thread hunt across SOFOS Managed

34
00:03:05,360 --> 00:03:12,960
Detection and Response telemetry. The SOFOS
MDRS Mark Parsons uncovered a complex, long

35
00:03:13,039 --> 00:03:17,000
running Chinese state sponsored cyber espionage operation
that they dubbed Crimson Palace, targeting a

36
00:03:17,080 --> 00:03:23,400
high profile government organization in the Southeast
Asia area. They have not specified who

37
00:03:23,439 --> 00:03:28,039
it was in Southeast Asia as of
yet. At least that's it for now
