Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
🇨🇳 CN13 malware families

Unfading Sea Haze

Also known asUnfading Sea Haze

Unfading Sea Haze is a Bitdefender-tracked espionage threat actor assessed as Chinese-nexus/China-aligned, with activity traced back to at least 2018. The group has targeted primarily government and military organizations in countries in the South China Sea region, with at least eight victims reported. Reporting describes the actor as focused on long-term access and repeated re-compromise of victim environments, with targeting and operations aligned with Chinese interests. Bitdefender reported no clear public linkage to a previously identified actor, but noted use of Gh0st RAT-derived tooling common in the Chinese cyber ecosystem and an isolated technique similarity to an APT41-linked backdoor. Other reporting linked related activity overlaps to Sophos Cluster Bravo/STAC1807 and Palo Alto Networks CL-STA-1049. EtherealGh0st is associated with Unfading Sea Haze, and FluffyGh0st is also reported as associated with the group. Observed initial access and delivery included spear-phishing emails delivering malicious ZIP archives containing LNK files disguised as documents, with lures observed in 2023 and March 2024, including Microsoft Defender-themed and U.S. political themes. One LNK chain checked for the ESET process ekrn.exe before proceeding. The actor also used a fileless technique in which PowerShell launched MSBuild.exe with a working directory on a remote SMB share so a remote project file executed in memory; SerialPktdoor was identified in this chain. The original initial compromise vector for older intrusions remains unknown. Persistence and access maintenance included scheduled tasks with names mimicking legitimate Windows components, DLL sideloading, abuse of the Windows Perception Simulation Service via a malicious hid.dll, manipulation of local Administrator accounts by enabling the account, resetting its password, and hiding it via the Winlogon SpecialAccounts\UserList registry key, and use of the commercial ITarian RMM tool since at least September 2022. Bitdefender also found indications of possible persistence on IIS and Apache httpd web servers, though the exact mechanism was not confirmed. Tooling reported from 2018 to 2023 included SilentGh0st, TranslucentGh0st, SharpJSHandler, and the Ps2dllLoader loader. Starting in 2023, the actor shifted toward more modular and fileless tradecraft, including FluffyGh0st, InsidiousGh0st, and EtherealGh0st. Additional custom tooling included xkeylog, a browser data stealer, a USB/WPD monitoring tool, and DustyExfilTool. Reported capabilities included command execution, file and folder manipulation, upload/download, data harvesting, keylogging, browser data theft, and exfiltration. Exfiltration reportedly evolved from DustyExfilTool over TLS/TCP through January 2022 to curl and FTP, later using more frequently changed randomly generated FTP credentials. Related reporting noted overlap between Unfading Sea Haze and activity clusters in other investigations. Sophos reported Cluster Bravo's CCoreDoor overlapped with Bitdefender's EtherealGh0st/Unfading Sea Haze reporting, including shared infrastructure. Palo Alto Networks reported CL-STA-1049 used a novel Hypnosis loader in a DLL sideloading chain to deploy what was assessed as likely FluffyGh0st, with strong overlap to Unfading Sea Haze.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Military

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics52 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1133
External Remote Services
T1566
Phishing
T1566.001×2
Spearphishing Attachment
TA0002
Execution
6 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059×2
Command and Scripting Interpreter
T1059.001
PowerShell
T1127
Trusted Developer Utilities Proxy Execution
T1127.001
MSBuild
T1129
Shared Modules
T1204
User Execution
T1204.002
Malicious File
T1574
Hijack Execution Flow
T1574.001
DLL
TA0003
Persistence
4 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1133
External Remote Services
T1136
Create Account
T1136.001
Local Account
T1505
Server Software Component
T1505.003×2
Web Shell
T1505.004
IIS Components
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1055
Process Injection
TA0005
Stealth
6 techniques
T1055
Process Injection
T1127
Trusted Developer Utilities Proxy Execution
T1127.001
MSBuild
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
T1564
Hide Artifacts
T1564.002
Hidden Users
T1574
Hijack Execution Flow
T1574.001
DLL
T1620
Reflective Code Loading
TA0006
Credential Access
2 techniques
T1056
Input Capture
T1056.001×2
Keylogging
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
TA0007
Discovery
2 techniques
T1082
System Information Discovery
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.002
SMB/Windows Admin Shares
TA0009
Collection
2 techniques
T1056
Input Capture
T1056.001×2
Keylogging
T1119
Automated Collection
TA0011
Command and Control
4 techniques
T1071×2
Application Layer Protocol
T1105
Ingress Tool Transfer
T1219×2
Remote Access Tools
T1568
Dynamic Resolution
TA0010
Exfiltration
1 technique
T1048
Exfiltration Over Alternative Protocol
IOCS

Observables

13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping30

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal13

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables13

Domains, IPs, and hashes tied to this actor, refreshed continuously.