Cluster Charlie is a China-linked cyberespionage activity cluster associated with Operation Crimson Palace, a state-directed intrusion campaign focused on Southeast Asia. It was initially observed inside a high-level government organization in an unnamed Southeast Asian country during 2023 and later resumed operations, expanding activity against additional government and public-service organizations in the region. Reporting assesses that Cluster Charlie operates as part of a broader coordinated threat organization alongside Cluster Alpha and Cluster Bravo, with ties to previously identified Chinese state-backed activity including links noted to APT15 and a subgroup of APT41 sometimes referred to as Earth Longzhi. Cluster Charlie’s operations are characterized by sustained persistence, repeated re-entry after disruption, and adaptive tradecraft. After custom command-and-control tooling was blocked, the operators shifted heavily to open-source and commodity frameworks including Cobalt Strike, Havoc, Impacket, SharpHound, Donut, XieBroC2, ExecIT, Alcatraz, RealBlindingEDR, and Cloudflared. The cluster repeatedly used stolen credentials, web shells on internet-facing application servers, scheduled tasks, WMIC, and remote execution to maintain footholds and move laterally. It also relied extensively on DLL sideloading and DLL hijacking through numerous execution chains, frequently rotating loaders, host processes, and payload combinations to evade detection. The cluster demonstrated strong defense-evasion capability. Observed behavior included endpoint-protection reconnaissance, querying security-product configuration, disabling or degrading telemetry, use of modified EDR-killer tooling, and exploitation of CVE-2023-38817 via a vulnerable driver to interfere with defensive products and elevate privileges. Operators also tested alternate payload variants and rapidly changed command-and-control channels and deployment methods when detections occurred. Cluster Charlie conducted broad internal reconnaissance and post-compromise discovery, including Active Directory mapping with SharpHound, service enumeration for sideloading opportunities, validation of remote-login success, and collection of system, network, and authentication information. It accessed administrative accounts and hypervisor infrastructure, created scheduled tasks for execution and pivoting, and used unmanaged devices and compromised regional organizations as staging or relay points to blend with trusted traffic patterns. Its collection objectives were consistent with intelligence gathering. Observed theft included administrator credentials, sensitive documents, cloud infrastructure material, backup and disaster-recovery keys, certificates, authentication material, network and IT configuration data, browser data, and internal communications databases. Cluster Charlie also deployed multiple keyloggers, including the previously undocumented TattleTale malware. TattleTale can fingerprint systems, enumerate drives, collect domain-controller and policy-related information, and harvest browser and storage data, supporting both credential access and broader intelligence collection. Overall, Cluster Charlie is best understood as a persistent Chinese cyberespionage cluster specializing in long-duration access, defense evasion, lateral movement, and targeted data theft against government and related regional entities in Southeast Asia.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Primary active cluster in the later phase of Operation Crimson Palace, focused on re-establishing footholds, bypassing EDR, rotating C2 infrastructure, conducting reconnaissance, lateral movement, credential theft, keylogging, and exfiltrating intelligence-value data from the target environment.
Primary active intrusion cluster in the second phase of Operation Crimson Palace, focused on re-establishing footholds, bypassing EDR, rotating C2 tooling, conducting reconnaissance, deploying keyloggers, and exfiltrating intelligence-relevant data.
Sophos-tracked cluster in the Crimson Palace campaign; targeted a high-level Southeast Asian government entity, went dormant and reemerged, and adopted tactics attributed to the other clusters—supporting the assessment of a shared overarching organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.