PULSE NAME
Operation Specter: An Active Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia
WHITE CL-STA-0043 AlienVault 2024-05-23 Modified: 2024-06-22
22
IOCs
MEDIUM VOLUME
An analysis reveals long-term espionage operations by a Chinese advanced persistent threat (APT) group against at least seven governmental entities across the Middle East, Africa and Asia since late 2022. The threat actor attempts to obtain sensitive and classified information about diplomatic and economic missions, embassies, military operations, political meetings, ministries and high-ranking officials. The campaign leverages rare email exfiltration techniques against compromised servers and utilizes previously undocumented backdoors named TunnelSpecter and SweetSpecter. The actor closely monitors geopolitical developments, exfiltrating information daily, and maintains persistence through repeated attempts when disrupted. The tactics, infrastructure and malware have strong connections to Chinese state-aligned interests.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
TunnelSpecter SweetSpecter gh0st RAT - S0032 Mydoor Moudoor
Indicators of Compromise (22)
All CVE FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2021-26855 2024-05-23
CVE CVE-2021-34473 2024-05-23
FileHash-SHA256 0b980e7a5dd5df0d6f07aabd6e7e9fc2e3c9e156ef8c0a62a0e20cd23c333373 2024-05-23
FileHash-SHA256 0e0b5c5c5d569e2ac8b70ace920c9f483f8d25aae7769583a721b202bcc0778f 2024-05-23
FileHash-SHA256 0f72e9eb5201b984d8926887694111ed09f28c87261df7aab663f5dc493e215f 2024-05-23
FileHash-SHA256 22d556db39bde212e6dbaa154e9bcf57527e7f51fa2f8f7a60f6d7109b94048e 2024-05-23
FileHash-SHA256 3d74df40e3d2730941ff64f275217ae6d46b20d7fbbd04123bc156daf8f6e85c 2024-05-23
FileHash-SHA256 62dec3fd2cdbc1374ec102d027f09423aa2affe1fb40ca05bf742f249ad7eb51 2024-05-23
FileHash-SHA256 8198c8b5eaf43b726594df62127bcb1a4e0e46cf5cb9fa170b8d4ac2a4dad179 2024-05-23
FileHash-SHA256 d5a44380e4f7c1096b1dddb6366713aa8ecb76ef36f19079087fc76567588977 2024-05-23
domain airjaldinet.ml 2024-05-23
domain govm.tk 2024-05-23
domain govu.ml 2024-05-23
domain microsoft-ns1.com 2024-05-23
hostname api.microsoft-ns1.com 2024-05-23
hostname cloud.microsoft-ns1.com 2024-05-23
hostname home.microsoft-ns1.com 2024-05-23
hostname labour.govu.ml 2024-05-23
hostname poer.whoamis.info 2024-05-23
hostname safer.ddns.us 2024-05-23
hostname static.microsoft-ns1.com 2024-05-23
hostname update.microsoft-ns1.com 2024-05-23