Weaver Ant is a China-nexus cyber espionage threat actor associated with a long-running intrusion against a major telecommunications provider in Asia. The actor’s objective was to obtain and maintain continuous access to telecommunications environments in order to collect sensitive information. Activity attributed to Weaver Ant has demonstrated exceptional persistence, with access reportedly maintained for more than four years and repeated attempts to re-establish footholds after remediation. Weaver Ant’s tradecraft is centered on extensive use of web shells for persistence, remote code execution, and lateral movement. Observed tooling included encrypted variants of China Chopper and a previously undocumented in-memory web shell referred to as INMemory. The latter executed a payload entirely in memory and dynamically ran attacker-supplied code after validating specially crafted HTTP headers. The actor also used recursive HTTP tunneling through chains of web shells to proxy traffic into internal environments, enabling stealthy movement between internal and external-facing IIS servers. The group employed multiple defense-evasion techniques, including encrypted payload delivery, in-memory execution, ETW patching to suppress telemetry, and AMSI bypasses. It executed PowerShell functionality through .NET assemblies without launching the standard PowerShell process. For internal expansion, Weaver Ant used SMB-based movement with valid high-privilege local or domain credentials and NTLM hashes, and conducted Active Directory reconnaissance with tooling such as Invoke-SharpView. The actor also harvested credentials and server-role information from IIS logs and configuration data, staged reconnaissance outputs for compression, and exfiltrated collected information. Attribution indicators align Weaver Ant with a China-nexus intrusion set, including its target profile, use of China Chopper, GMT+8 working patterns, and use of an operational relay box network built largely from compromised routers associated with Southeast Asian telecommunications providers. Weaver Ant is best characterized as a persistent, stealth-focused espionage actor specializing in long-term access to telecom networks through web-shell-based post-exploitation and lateral movement.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
85 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese state-sponsored intrusion set reported breaching an Asian telecommunications provider and maintaining long-term, stealthy persistence (multi-year dwell time).
China-nexus espionage activity targeting a major telecommunications company in Asia, using web shells for long-term persistence, web shell tunneling for lateral movement, stealth monitoring evasion, credential abuse, reconnaissance, and data collection/exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.