Weaver Ant is a China-nexus cyber-espionage threat actor tracked for a long-running intrusion against a major telecommunications provider in Asia. Its objective is assessed as maintaining continuous access to telecommunications environments to collect sensitive information, credentials, and network intelligence. The actor maintained access in the observed victim environment for more than four years and attempted to re-establish access after coordinated remediation. Weaver Ant relies heavily on web-shell-based tradecraft for persistence, remote execution, and lateral movement. It has used encrypted variants of China Chopper and INMemory, a memory-resident web shell capable of executing payloads without writing them to disk. The group uses recursive HTTP tunneling through web shells to proxy traffic between internal systems, alongside compromised customer-premises routers functioning as an operational relay-box network to obscure infrastructure and pivot across telecommunications environments. The actor has exploited public-facing applications for access; used valid local and domain accounts, credential material, token impersonation, SMB administrative shares, and transferred tools for lateral movement; and harvested credentials from account stores and server configuration material. It conducts Active Directory, account, network, share, host, and file-system discovery; stages and archives collected data; and exfiltrates data over alternative protocols. Defensive evasion has included in-memory execution, event-tracing suppression, antimalware scanning interface bypass, encrypted web-shell communications, and process injection. Weaver Ant exhibits characteristics consistent with China-nexus targeted espionage operations, including its target selection, working patterns, and infrastructure tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
85 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese state-sponsored intrusion set reported breaching an Asian telecommunications provider and maintaining long-term, stealthy persistence (multi-year dwell time).
China-nexus espionage activity targeting a major telecommunications company in Asia, using web shells for long-term persistence, web shell tunneling for lateral movement, stealth monitoring evasion, credential abuse, reconnaissance, and data collection/exfiltration.
Conducted a long-running cyber-espionage operation against an undisclosed Asian telecommunications provider, maintaining access for over four years to harvest credentials and gather network intelligence. It used compromised Zyxel CPE routers as an Operational Relay Box proxy network to conceal infrastructure and pivot across telecommunications organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.