Operation Diplomatic Specter
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Operation Diplomatic Specter is a cyber espionage campaign that emerged in late 2022, initially tracked by Palo Alto Networks as CL-STA-0043 and later as TGR-STA-0043 before the actor behind it was formally named Phantom Taurus. This Chinese state-aligned threat group focuses on intelligence collection, specifically targeting sensitive information related to military operations, diplomatic missions, embassies, and foreign affairs ministries. The group distinguishes itself through the use of rare email exfiltration techniques against compromised servers and the deployment of unique, custom-built backdoors like TunnelSpecter and SweetSpecter, along with in-memory VBScript implants. Its operations are characterized by an adaptive approach to evade detection, often adjusting tactics to circumvent mitigation efforts.