Soft Cell is a China state-aligned cyber-espionage activity group assessed by Cybereason (high confidence) as operating in the interest of China. In intrusions observed from 2018 through at least Q1 2021 (with indications continuing into mid-2021), Soft Cell targeted telecommunications providers across Southeast Asia/ASEAN, aiming to obtain and maintain long-term access for espionage—specifically targeting billing servers containing Call Detail Record (CDR) data, as well as Domain Controllers, web servers, and Microsoft Exchange servers. Initial access in the described clusters was achieved via exploitation of Microsoft Exchange Server vulnerabilities similar to those used in the HAFNIUM campaign, followed by deployment of webshells (notably China Chopper) on compromised Exchange servers. Post-compromise tradecraft included staging tools in $RECYCLE.BIN for evasion; extensive use of built-in Windows utilities for reconnaissance (e.g., net, whoami, tasklist, hostname, ping) and additional tooling such as PortQry (renamed to psc.exe) and Sysinternals PsLogList for reconnaissance/log collection. Credential theft was performed with Mimikatz, including PowerShell Empire Invoke-Mimikatz. Lateral movement and remote execution leveraged WMI, net use, and remote scheduled tasks. Soft Cell used Cobalt Strike implants/loaders and relied on the PcShare backdoor, executed via a loader DLL (NvSmartMax.dll) and payload (NvSmartMax.dat) masquerading as NVIDIA components, commonly side-loaded using a legitimate executable (nvSmarEx.exe) and sometimes executed via rundll32.exe. Defense evasion included timestomping via PowerShell to alter file creation times. Persistence/covert access included deploying SoftEther VPN renamed to oracll.exe. Collection/exfiltration included gathering local data such as password hashes from the SAM registry hive, compressing and password-protecting stolen data with WinRAR, and exfiltrating it via the China Chopper webshell; operators also enabled the built-in Windows account SUPPORT_388945a0 and used its Documents folder to stage exfiltration archives. The content also notes Soft Cell used a modified nbtscan for NetBIOS discovery and leveraged valid accounts to maintain access, and that some Soft Cell payloads were packed using a mix of known and custom packers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stages additional administrative and tunneling tools on victim systems during operations.
Uses modified HTRAN with obfuscated strings/debug messages for evasion.
Network discovery using native commands and modified scanning tooling to identify NetBIOS infrastructure.
Uses web shells and HTRAN for command-and-control and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.