Security researchers reported multiple long-running China-nexus intrusions against telecommunications providers in Asia and Southeast Asia, with attackers seeking persistent access to core networks and sensitive data. Sygnia said a threat actor it tracks as Weaver Ant remained inside a major Asian telecom for more than four years, using encrypted China Chopper variants, a newly described in-memory web shell called INMemory, and recursive HTTP tunneling to maintain stealthy remote access and move laterally. Cybereason separately documented three intrusion clusters affecting major telcos across ASEAN countries, linking activity with varying confidence to Soft Cell, Naikon, and APT27/Group-3390, and said the operators targeted domain controllers, billing systems, Exchange servers, and web servers to support cyber-espionage objectives.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Cybereason investigated three intrusion clusters targeting telecommunications providers in Southeast Asia and ASEAN countries in early 2021. The attackers exploited Microsoft Exchange vulnerabilities and compromised assets including domain controllers, billing servers, web servers, and Exchange servers for espionage.
Cybereason said Cluster B was first observed in the fourth quarter of 2020 and continued through the first quarter of 2021. The cluster was attributed with moderate confidence to Naikon APT and included use of the Nebulae backdoor.
Cybereason reported that Cluster A activity began in 2018 and continued through the first quarter of 2021. It attributed the cluster with high confidence to Soft Cell, a China-aligned espionage activity group targeting telecom networks.
Cisco Talos said it observed significant China Chopper activity over a two-year period beginning in June 2017. The activity spanned multiple campaigns involving IIS and Apache servers and a range of post-compromise objectives.
Cybereason reported that Cluster C, a custom Outlook Web Access backdoor on Microsoft Exchange and IIS servers, had earliest evidence dating to 2017. The activity was assessed with low-to-moderate confidence as related to Group-3390/APT27.
After coordinated eradication efforts, Sygnia detected Weaver Ant attempting to regain access to the victim environment. The follow-on activity underscored the actor's persistence and continued reliance on web-shell-based tradecraft.
During its investigation, Sygnia identified a previously undocumented web shell it named INMemory and described Weaver Ant's recursive HTTP tunneling technique using chained web shells as proxies. The tooling enabled in-memory execution, stealthy command delivery, and lateral movement across internal and external IIS servers.
Sygnia said the intrusion was discovered after a previously disabled account used by the threat actor was re-enabled by a service account from a server not previously known to be compromised. Investigators then found a China Chopper variant on an internal server that had been compromised for several years.
Sygnia reported that a China-nexus actor it tracks as Weaver Ant had maintained access to a major telecommunications company in Asia for more than four years. The campaign relied on encrypted China Chopper variants and a previously undocumented in-memory web shell called INMemory to preserve access and move laterally.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
sygnia.co
Open sourcecybereason.com
Open sourceblog.talosintelligence.com
Open sourceattack.mitre.org
Open sourcecybereason.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.