Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure
A Chinese threat actor has conducted a years-long campaign targeting high-value organizations across South, Southeast, and East Asia in critical infrastructure sectors including aviation, energy, government, and telecommunications. The campaign leverages web server exploits and Mimikatz for credential extraction and lateral movement. Palo Alto Networks Unit 42 has attributed this activity to a previously undocumented threat group.
Summary
A Chinese threat actor has conducted a years-long campaign targeting high-value organizations across South, Southeast, and East Asia in critical infrastructure sectors including aviation, energy, government, and telecommunications. The campaign leverages web server exploits and Mimikatz for credential extraction and lateral movement. Palo Alto Networks Unit 42 has attributed this activity to a previously undocumented threat group.
Indicators of Compromise
- malware — Mimikatz