Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
🇨🇳 CN7 malware families

Crimson Palace

Also known ascrimson_palace

Crimson Palace is a Chinese state-sponsored cyberespionage operation/campaign identified by Sophos MDR, targeting a high-profile government organization in Southeast Asia. Sophos reported related activity from early 2022 through at least April 2024 and assessed with high confidence that the objective was long-term espionage in support of Chinese state interests, including collection of military, political, technical, and infrastructure-related information. Reported collection included documents related to South China Sea strategies, infrastructure architecture data, and credentials or tokens. Sophos tracked at least three intrusion clusters within Crimson Palace: Cluster Alpha (STAC1248), Cluster Bravo (STAC1807), and Cluster Charlie (STAC1305). Sophos assessed with moderate confidence that these were distinct but coordinated actors operating with shared objectives under a central authority. Cluster Alpha focused on DLL sideloading, persistent C2, subnet and Active Directory reconnaissance, and service-based persistence using instsrv.exe and srvany.exe. Cluster Bravo used valid accounts for lateral movement and deployed the CCoreDoor backdoor for persistence, discovery, credential dumping, and external C2. Cluster Charlie deployed multiple PocoProxy implants, conducted mass Event Log analysis and large-scale ping sweeps, used a custom HUI loader to inject Cobalt Strike into mstsc.exe, injected an LSASS logon credential interceptor into svchost.exe on domain controllers, and later re-entered the victim network via a web shell after defensive disruption. The campaign used extensive DLL sideloading, with more than 15 distinct sideloading scenarios involving Windows services, Microsoft binaries, and antivirus vendor software. Sophos identified previously unreported malware families CCoreDoor and PocoProxy, as well as an updated EAGERBEE variant capable of disrupting communications with antivirus vendor domains. Additional tooling observed in the campaign included NUPAKAGE, Merlin C2 Agent, Cobalt Strike, PhantomNet, RUDEBIRD, and PowHeartBeat. Sophos also reported advanced evasion, including overwriting ntdll.dll in memory to unhook the Sophos AV agent process from the kernel. Sophos reported overlaps between Crimson Palace activity and publicly reported China-affiliated actors or reporting on Earth Estries, REF5961, BackdoorDiplomacy, Worok/TA428, Unfading Sea Haze, and Earth Longzhi (APT41 subgroup), but explicitly refrained from high-confidence attribution to a single known actor because of shared infrastructure and tooling across Chinese operations. The alias directly supported in the content is Crimson Palace.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Military

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics16 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0002
Execution
2 techniques
T1059×2
Command and Scripting Interpreter
T1129
Shared Modules
TA0004
Privilege Escalation
1 technique
T1055
Process Injection
TA0005
Stealth
1 technique
T1055
Process Injection
TA0006
Credential Access
1 technique
T1056
Input Capture
T1056.001
Keylogging
TA0007
Discovery
2 techniques
T1016
System Network Configuration Discovery
T1083
File and Directory Discovery
TA0009
Collection
2 techniques
T1056
Input Capture
T1056.001
Keylogging
T1115
Clipboard Data
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1105
Ingress Tool Transfer
T1219
Remote Access Tools
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
ACTIVITY FEED

Recent activity

9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping11

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal7

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.