A Chinese state-linked hacking group tracked as APT10 was tied to a months-long supply-chain intrusion against Taiwan’s financial sector, compromising organizations through an undisclosed flaw in the web administration interface of a widely used securities software product. Researchers said the affected platform reportedly serves more than 80% of Taiwan’s local financial organizations, giving the attackers broad downstream access. The campaign, tracked as Operation Cache Panda, was disguised in part as credential-stuffing activity while targeting brokerage data, personally identifiable information, and the ability to disrupt investment operations rather than steal funds directly.
After initial access, the attackers uploaded the ASPXCSharp web shell to control exposed servers, used Impacket to scan internal networks, and moved laterally with Remote Service creation and WMI. They then deployed a Quasar RAT variant and other .NET payloads through reflective in-memory loading using tooling associated with Donut and SharpSploit, reducing on-disk artifacts and antivirus detection. Investigators also found the group established reverse-tunnel RDP access for persistent interactive control and used the Chinese cloud file-sharing service WenShuShu to retrieve tools during the operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CyCraft reported that one of its customers was compromised in February 2022, which helped investigators determine that what appeared to be separate attack waves were actually one prolonged campaign. The investigation linked the activity to the broader Operation Cache Panda intrusion set.
CyCraft said the intrusion campaign against Taiwanese financial organizations began at the end of November 2021. The attackers exploited a vulnerability in the web management interface of a widely used securities/security software product to gain initial access.
Symantec reported that a China-linked group tracked as Antlion remained inside an unnamed Taiwanese financial organization for close to 250 days, from December 2020 to August 2021, as part of an espionage campaign. The intrusion involved the custom xPack backdoor, which enabled command execution, malware delivery, and data staging for exfiltration.
CyCraft assessed that the campaign targeting Taiwan's financial sector was conducted by APT10, a Chinese government-affiliated cyber-espionage group. Reporting described the operation as a supply-chain style intrusion affecting multiple enterprises through a widely deployed software product.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcetherecord.media
Open sourcethehackernews.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.