Unit 42 has documented a previously undisclosed Chinese threat actor cluster, CL-UNK-1068, conducting cyberespionage operations against critical sectors (aviation, energy, government, telecom, pharma) across South, Southeast, and East Asia since at least 2020. The group uses a cross-platform toolkit combining custom malware

20m read time From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryTechnical Analysis OverviewInitial Access and Web Shell DeploymentExfiltrating Configuration Files for Access and Sensitive DataTool SetConclusionIndicators of CompromiseAdditional ResourcesAppendix A: AttributionAppendix B: CL-UNK-1068 Tools and Utilities

Sort: