Crimson Palace
Crimson Palace is a Chinese state-sponsored cyberespionage operation/campaign identified by Sophos MDR, targeting a high-profile government organization in Southeast Asia. Sophos reported related activity from early 2022 through at least April 2024 and assessed with high confidence that the objective was long-term espionage in support of Chinese state interests, including collection of military, political, technical, and infrastructure-related information. Reported collection included documents related to South China Sea strategies, infrastructure architecture data, and credentials or tokens. Sophos tracked at least three intrusion clusters within Crimson Palace: Cluster Alpha (STAC1248), Cluster Bravo (STAC1807), and Cluster Charlie (STAC1305). Sophos assessed with moderate confidence that these were distinct but coordinated actors operating with shared objectives under a central authority. Cluster Alpha focused on DLL sideloading, persistent C2, subnet and Active Directory reconnaissance, and service-based persistence using instsrv.exe and srvany.exe. Cluster Bravo used valid accounts for lateral movement and deployed the CCoreDoor backdoor for persistence, discovery, credential dumping, and external C2. Cluster Charlie deployed multiple PocoProxy implants, conducted mass Event Log analysis and large-scale ping sweeps, used a custom HUI loader to inject Cobalt Strike into mstsc.exe, injected an LSASS logon credential interceptor into svchost.exe on domain controllers, and later re-entered the victim network via a web shell after defensive disruption. The campaign used extensive DLL sideloading, with more than 15 distinct sideloading scenarios involving Windows services, Microsoft binaries, and antivirus vendor software. Sophos identified previously unreported malware families CCoreDoor and PocoProxy, as well as an updated EAGERBEE variant capable of disrupting communications with antivirus vendor domains. Additional tooling observed in the campaign included NUPAKAGE, Merlin C2 Agent, Cobalt Strike, PhantomNet, RUDEBIRD, and PowHeartBeat. Sophos also reported advanced evasion, including overwriting ntdll.dll in memory to unhook the Sophos AV agent process from the kernel. Sophos reported overlaps between Crimson Palace activity and publicly reported China-affiliated actors or reporting on Earth Estries, REF5961, BackdoorDiplomacy, Worok/TA428, Unfading Sea Haze, and Earth Longzhi (APT41 subgroup), but explicitly refrained from high-confidence attribution to a single known actor because of shared infrastructure and tooling across Chinese operations. The alias directly supported in the content is Crimson Palace.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Military
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with multiple attacks against government organizations in Southeast Asia.
China-aligned espionage campaign referenced as overlapping with CL-STA-1048 and CL-STA-1049 through shared tooling such as Masol RAT and FluffyGh0st.
Chinese state-sponsored cyberespionage campaign targeting a Southeast Asian government organization to maintain long-term access, conduct reconnaissance, collect sensitive military and technical information, and sustain redundant C2 access.
Chinese state-sponsored cyberespionage campaign against a Southeast Asian government organization, focused on long-term access, reconnaissance, credential theft, and exfiltration of sensitive military/political documents, using extensive DLL sideloading, multiple redundant C2 implants, and evasion (including in-memory unhooking).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.