EXECUTIVE SUMMARY
Researchers has uncovered concerning cyber espionage activities targeting entities and member countries associated with the Association of Southeast Asian Nations (ASEAN). Two Chinese Advanced Persistent Threat (APT) groups, namely Stately Taurus and another unnamed group, have been identified as the perpetrators behind these malicious campaigns. Stately Taurus, also known as Mustang Panda and BRONZE PRESIDENT, has a history of targeting government entities and nonprofits across North America, Europe, and Asia since at least 2012. These attacks coincide with significant events such as the ASEAN-Australia Special Summit, raising alarms about the security of sensitive diplomatic and economic information in the region.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Researchers has uncovered concerning cyber espionage activities targeting entities and member countries associated with the Association of Southeast Asian Nations (ASEAN). Two Chinese Advanced Persistent Threat (APT) groups, namely Stately Taurus and another unnamed group, have been identified as the perpetrators behind these malicious campaigns. Stately Taurus, also known as Mustang Panda and BRONZE PRESIDENT, has a history of targeting government entities and nonprofits across North America, Europe, and Asia since at least 2012. These attacks coincide with significant events such as the ASEAN-Australia Special Summit, raising alarms about the security of sensitive diplomatic and economic information in the region.[emaillocker id="1283"]
Stately Taurus, in their recent campaigns, exhibited a high level of sophistication in their attack vectors. One notable instance involved the distribution of malware packaged as innocuous files. For example, the "Talking_Points_for_China.zip" package disguised a malicious executable, masquerading as an anti-keylogging tool developed by QFX Software Corporation. Upon execution, this binary sideloaded a malicious Dynamic Link Library (DLL) and initiated a connection to a Command and Control (C2) server. Similarly, another package, "Note PSO.scr," employed a screensaver executable to deliver malicious payloads. This tactic, a deviation from their typical use of archive formats, aimed to evade detection. In addition to Stately Taurus' activities, the second Chinese APT group displayed consistent patterns of cyber espionage targeting ASEAN-affiliated entities. This group's infrastructure, comprising various IP addresses and domains, facilitated malicious activities including data exfiltration and command and control operations.
The discovery of these cyber espionage campaigns underscores the ongoing threat posed by nation-state affiliated APT groups to organizations and governments within the ASEAN region. These attacks emphasize the importance of implementing robust cybersecurity measures to safeguard sensitive information and defend against sophisticated threat actors. Organizations are urged to remain vigilant and leverage intelligence insights to bolster their defense against evolving cyber threats.
THREAT PROFILE:

REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/03/two-chinese-apt-groups-ramp-up-cyber.html
[/emaillocker]