A China-linked espionage group tracked as Cicada/APT10 exploited Microsoft’s Zerologon flaw, CVE-2020-1472, in a long-running campaign against major Japanese companies and some overseas subsidiaries, including entities in the United States. Researchers said the attackers used the bug to compromise domain controllers, steal domain credentials, and effectively seize control of Active Directory environments, enabling credential theft, network reconnaissance, data exfiltration, and persistent access across victim networks.
The operation combined public exploit activity around Zerologon with a broader post-compromise toolkit that included QuasarRAT, the newly observed Backdoor.Hartip, DLL side-loading, and administrative utilities such as WMIExec, Certutil, and PowerShell. Separate honeypot telemetry also showed in-the-wild Zerologon exploitation against exposed internet systems, underscoring how quickly the vulnerability moved from disclosure to active abuse while APT10 leveraged distinctive tradecraft such as CppHostCLR-based .NET loader execution and ConfuserEx obfuscation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
At 11:01 UTC on the reported day, IP address 124.70.137.246 attempted to exploit CVE-2020-1472 against the BluePot honeypot, triggering an Azure Sentinel alert. The source IP was identified via Shodan as belonging to Huawei Cloud Service.
Symantec said the Cicada espionage operation continued until the beginning of October 2020, with attackers remaining on some victim networks for close to a year. During the campaign, the group exploited Zerologon, compromised domain controllers and file servers, and deployed QuasarRAT and Backdoor.Hartip.
Microsoft disclosed and patched the Netlogon elevation-of-privilege flaw CVE-2020-1472, known as Zerologon. The bug could allow attackers to spoof a domain controller account, steal credentials, and fully compromise Active Directory.
Symantec reported that the China-linked Cicada/APT10 group began a large-scale espionage campaign targeting major Japanese companies and some subsidiaries, including locations in the United States. The operation involved credential theft, reconnaissance, persistence, and data exfiltration.
Symantec reported and attributed the long-running campaign against Japanese-linked organizations to the China-linked Cicada/APT10 group based on tooling and tradecraft, including DLL side-loading, a distinctive DLL export name, CppHostCLR-based loader execution, ConfuserEx obfuscation, and QuasarRAT delivery.
The DoublePulsar author said they detected an attacker exploiting Zerologon on a personal honeypot about three weeks before the later BluePot observation. This was cited as earlier evidence of in-the-wild exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
threatpost.com
Open sourcedoublepulsar.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.