Operation Crimson Palace: A Technical Deep Dive

Credit to Author: gallagherseanm| Date: Wed, 05 Jun 2024 10:00:46 +0000

Sophos Managed Detection and Response initiated a threat hunt across all customers after the detection of abuse of a vulnerable legitimate VMware executable (vmnat.exe) to perform dynamic link library (DLL) side-loading on one customer’s network. In a search for similar incidents in telemetry, MDR ultimately uncovered a complex, persistent cyberespionage campaign targeting a high-profile government […]

Read more

Operation Crimson Palace: Sophos threat hunting unveils multiple clusters of Chinese state-sponsored activity targeting Southeast Asian government

Credit to Author: gallagherseanm| Date: Wed, 05 Jun 2024 10:00:34 +0000

Threat clusters targeted a government agency for cyberespionage in a campaign that had precursors dating back to early 2022.

Read more