Cluster Bravo is one of three intrusion clusters associated with Operation Crimson Palace, a Chinese state-directed cyberespionage campaign focused on Southeast Asia. It has been tracked alongside Cluster Alpha and Cluster Charlie, and the overlap in tooling, tradecraft, and operational patterns indicates orchestration by a broader common threat organization. Reporting also links the broader activity set to previously identified Chinese state-backed ecosystems including APT15 and a subgroup of APT41 sometimes referred to as Earth Longzhi, although Cluster Bravo itself is presented as an operational cluster within Crimson Palace rather than a standalone legacy actor name. Cluster Bravo was initially observed inside a high-level Southeast Asian government environment during 2023 and was later detected on at least 11 additional organizations and agencies in the same region. Its expansion activity from January through June 2024 affected government entities, non-governmental public service organizations, and private organizations with government-related roles. A notable operational characteristic of the campaign was the use of already compromised regional organizations as trusted staging and relay points, often selecting infrastructure from the same sector as the intended victim to improve plausibility and reduce suspicion. The broader Crimson Palace activity associated with Cluster Bravo emphasized intelligence collection rather than disruption. Victimology and follow-on operations indicate targeting of government and public service networks for espionage purposes, with collection priorities across the campaign including sensitive documents, administrator credentials, cloud and backup keys, certificates, internal communications, and network configuration data. The operators repeatedly sought to preserve or regain access after defensive disruption and adapted their tooling when detections increased. Across the campaign, associated operators used reconnaissance, credential theft, persistence, lateral movement, DLL sideloading, web shells, scheduled tasks, remote execution, and defense-evasion techniques. They also relied heavily on open-source and commodity frameworks such as Cobalt Strike, Havoc, SharpHound, Impacket, Donut, XiebroC2, ExecIT, Alcatraz, Cloudflared, and RealBlindingEDR, and deployed keylogging capability including the previously undocumented TattleTale malware. The campaign’s operational behavior reflects a mature espionage actor able to rotate infrastructure and deployment chains quickly, abuse trusted relationships between regional organizations, and sustain long-running access across multiple victim networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Expanded activity cluster within Operation Crimson Palace observed across at least 11 additional regional organizations and agencies, using compromised same-vertical infrastructure for malware staging, C2 relay, and operational support.
Expanded intrusion cluster within Operation Crimson Palace observed across at least 11 additional regional organizations and agencies, using compromised same-vertical infrastructure for malware staging and relay.
Sophos-tracked cluster in the Crimson Palace campaign; activity persisted after disruption and expanded to additional organizations across Southeast Asia, consistent with state-aligned espionage operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.