ReliaQuest investigated an intrusion at an unnamed US defense technology company in February 2025, attributing it to a Chinese advanced persistent threat group with medium-high confidence. Attackers initially exploited SharePoint vulnerabilities and, 15 days after losing access, re-entered through vulnerable Ivanti Pulse Secure devices. They used compromised service accounts, SMB, chained web shells, and obfuscated in-memory execution to reach sensitive SFTP servers while disabling logging and concealing activity. Persistence included permanent WMI event consumers, modified Globalscape files, and suspected web shells on Ivanti appliances. ReliaQuest assessed the operation as likely espionage aimed at defense and engineering intellectual property, but did not establish successful data exfiltration.
Separately, Palo Alto Networks Unit 42 reported Operation Diplomatic Specter, an active Chinese cyberespionage campaign using a rare toolset against government entities in the Middle East, Africa, and Asia. The reports describe Chinese espionage targeting both government information and sensitive defense technology, without establishing a shared operator or campaign. For defenders, the defense-sector intrusion highlights the importance of patching internet-facing SharePoint and Ivanti systems, investigating compromised service accounts, and checking WMI persistence, Globalscape file integrity, and SFTP access. The attackers’ return through a different entry point also demonstrates why remediation must address alternative access paths rather than only the initial compromise.

See which actors are running it and whether you're in range.
12 events from the most recent confirmed update back to the earliest known activity.
In February 2025, ReliaQuest investigated the intrusion against the unnamed US-based defense technology customer. The attackers targeted an SFTP server containing network configurations, system backups, and proprietary defense-contract information.
ReliaQuest attributed the intrusion to an unspecified Chinese advanced persistent threat group with medium-high confidence and assessed its likely objective as stealing defense and engineering intellectual property. The report did not establish that data was successfully exfiltrated.
Attackers injected malicious code into legitimate Globalscape EFT files while preserving their original functionality to disguise persistent access. A crafted POST request to "favidon.ico" on the SFTP server's public-facing webpage could activate the backdoor and bypass authentication.
Attackers disabled logging on Ivanti appliances and wiped logs described by the report as Active Directory driver logs on an Exchange server. These actions concealed activity and obscured authentication and user-access trails.
Attackers installed a permanent WMI event consumer that checked for host changes every five seconds and executed a VBScript payload, providing persistence across reboots.
Attackers used WMI to execute obfuscated scripts in memory and repeatedly attempted to load scripts designed to write data to "C:\ProgramData\Templates.log" on domain controllers and subsequently the SFTP server. They also injected code into the legitimate "lbfoAdmin.exe" binary, bypassing EDR and supporting operations on the SFTP server.
During the Ivanti-based intrusion, attackers remotely modified "redirsuiteserviceproxy.aspx," "logon.aspx," and "logoff.aspx" to deploy web shells. The shells communicated with a compromised Ivanti device for command and control and were chained to traverse network segments.
Fifteen days after losing access, attackers exploited unspecified vulnerabilities in multiple unpatched, end-of-life Ivanti Pulse Secure devices. They used residential proxy IP addresses to conceal their traffic sources.
The attackers lost access following their initial intrusion. The report does not specify when or how that access was interrupted.
Attackers began lateral movement 21 hours after initial access, using compromised accounts and an SMB named pipe called "ntsvcs" to obtain extensive file-access and execution permissions on an SCCM server and a domain controller. RDP attempts against 27 hosts failed.
Twenty hours after the SharePoint compromise, attackers used compromised service accounts to scan the network and identify sensitive SFTP servers in preparation for lateral movement.
Attackers exploited multiple unspecified SharePoint vulnerabilities to compromise a server at an unnamed US defense technology company. They then brute-forced service accounts associated with SharePoint and Varonis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
reliaquest.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.