Cluster Alpha is one of three closely associated intrusion clusters identified within Operation Crimson Palace, a Chinese state-directed cyberespionage campaign focused on Southeast Asia. The cluster is assessed as part of a broader, coordinated threat organization operating alongside Cluster Bravo and Cluster Charlie, with reported ties to previously tracked Chinese state-backed activity including APT15 and a subgroup of APT41 sometimes referred to as Earth Longzhi. The campaign’s primary objective is intelligence collection against government and related regional organizations. Operation Crimson Palace targeted a prominent Southeast Asian government agency and expanded to additional government bodies, public service organizations, and other regional entities. The operators also used compromised organizations in the same region as staging and relay infrastructure, often selecting entities in the same sector as intended victims to make access appear trusted. Across the coordinated clusters, observed tradecraft included persistent access, reconnaissance, credential theft, web shell deployment, DLL sideloading and DLL hijacking, scheduled-task abuse, remote execution with Impacket tooling, Active Directory mapping with SharpHound, lateral movement through administrative mechanisms such as WMIC, use of open-source command-and-control frameworks including Havoc and Cobalt Strike, process injection, repeated defense evasion, and targeted collection and exfiltration of sensitive documents, administrator credentials, cloud and backup keys, certificates, internal communications data, and network configuration material. The broader operation also employed keylogging malware, including the previously undocumented TattleTale family, and used EDR-disabling tooling including RealBlindingEDR with BYOVD-style privilege escalation. Although the most detailed public reporting in this campaign centers on Cluster Charlie and expansion activity linked to Cluster Bravo, Cluster Alpha was observed operating inside the primary government victim during 2023 and is assessed to be part of the same overarching Chinese espionage apparatus based on overlapping tactics, tooling, and operational coordination. Its dominant motivation is espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated activity cluster within Operation Crimson Palace whose tactics overlapped with later Cluster Charlie activity, including use of Impacket atexec, service DLL sideloading, and EagerBee-related tradecraft.
Associated activity cluster within Operation Crimson Palace whose tactics overlapped with later Cluster Charlie activity, including remote execution and service/DLL sideloading tradecraft.
One of three Sophos-tracked clusters participating in the Crimson Palace cyberespionage campaign targeting government organizations in Southeast Asia, focused on persistent access and intelligence collection/exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.