A series of data exfiltration assaults aimed at Southeast Asia have been connected to a threat actor named CeranaKeeper that was previously unreported.
Using technologies previously identified as being employed by the Mustang Panda actor, the Slovak cybersecurity firm ESET concluded that the activity cluster was tied to China after seeing efforts that began in 2023 and targeted governmental entities in Thailand.
According to security researcher Romain Dumont’s analysis, which was published today, the gang varies its techniques to facilitate huge data exfiltration and changes its backdoor to avoid detection.
Using well-known, trustworthy cloud and file-sharing services like Dropbox and OneDrive, CeranaKeeper creates unique backdoors and extraction tools read more about China-Linked CeranaKeeper Targeting Southeast Asia with Data Exfiltration.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions
