Operation Crimson Palace is a Chinese state-directed cyberespionage operation targeting government agencies and public-service-related organizations in Southeast Asia. The activity has been associated with three linked clusters—Cluster Alpha, Cluster Bravo, and Cluster Charlie—which are assessed to be orchestrated by the same overarching threat organization based on overlapping tactics, tooling, and operational patterns. The operation has focused primarily on a prominent government agency in a Southeast Asian nation, while also affecting additional government entities, public service organizations, and private organizations with government-related roles in the same region. A notable operational characteristic is the use of compromised regional organizations as staging points and relay infrastructure, often selecting intermediary organizations in the same sector as the intended victim to increase trust and reduce suspicion. Observed tradecraft includes persistent access, reconnaissance, credential theft, keylogging, lateral movement, privilege escalation, defense evasion, and intelligence collection. The actors used stolen credentials to deploy web shells to internet-facing application servers through legitimate upload functionality, then leveraged those footholds to execute commands, inspect configurations, deploy additional payloads, and expand access across victim environments. They conducted Active Directory mapping with SharpHound, used WMIC and Impacket for remote execution and tasking, queried event logs to validate remote access, and collected administrator credentials, sensitive documents, cloud and backup keys, certificates, network configuration data, and internal communications. The intrusion set made extensive use of open-source and commodity tooling, including Cobalt Strike, Havoc, Impacket, SharpHound, Donut, XieBroC2, ExecIT, Alcatraz, RealBlindingEDR, and Cloudflared. DLL sideloading and DLL hijacking were central to payload delivery, with numerous rotating execution chains and shellcode loaders used to re-establish access and evade detection. The actors repeatedly changed command-and-control channels and deployment methods after defensive disruption. Defense evasion was particularly prominent. The operators probed endpoint protection configurations, queried exclusions and security-product artifacts, and deployed modified RealBlindingEDR components to impair endpoint defenses. Those components exploited CVE-2023-38817 via a vulnerable driver to disable or crash security tooling and facilitate privilege escalation. The campaign also used obfuscation and repeated variant testing to refine payload delivery. A previously undocumented keylogger, TattleTale, was used in the operation. TattleTale can fingerprint infected systems, enumerate drives, collect browser and storage data, and steal sensitive LSA policy information. Additional keylogging components were also deployed alongside mechanisms intended to suppress endpoint telemetry and access protected browser data. The campaign is best characterized as a sustained espionage-focused intrusion program rather than a financially motivated operation. Its emphasis on long-term persistence, stealthy access restoration, administrative credential capture, internal mapping, and collection of high-value government and infrastructure-related information is consistent with state-backed intelligence objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese state-directed cyberespionage campaign targeting a Southeast Asian government agency and additional regional government and public service organizations, using compromised regional infrastructure, custom malware, web shells, open-source C2 frameworks, credential theft, reconnaissance, lateral movement, EDR evasion, and data exfiltration.
Chinese state-directed cyberespionage campaign targeting government and public service organizations in a Southeast Asian region, using compromised regional infrastructure, custom malware, web shells, sideloading, credential abuse, reconnaissance, persistence, and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.