Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Lilac Typhoon

Also known as: DEV-0234

Description

Lilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which allows for remote code execution. This vulnerability has been used in cryptojacking campaigns and is included in commercial exploit frameworks. Lilac Typhoon has also been involved in deploying various payloads such as Cobalt Strike, web shells, botnets, coin miners, and ransomware.

AI Analysis

· 1 week ago

Executive Summary

Lilac Typhoon, also known as DEV-0234, is a likely state-sponsored threat actor attributed to China. They exploit vulnerabilities such as CVE-2022-26134 for financial gain through cryptojacking and other malicious activities.

Goals & Targeting

It appears Lilac Typhoon targets sectors with exposed Confluence servers across various industries, leveraging these vulnerabilities to extract data or deploying cryptojacking malware for profit. The primary motivation likely revolves around financial interests, with potential secondary goals of gathering intelligence.

Enhanced Description

Lilac Typhoon has demonstrated versatility by leveraging the Atlassian Confluence RCE vulnerability, which has enabled their campaigns involving cryptojacking, espionage, and ransomware deployment. Their use of tools like Cobalt Strike suggests a capability for targeted operations, potentially indicating a high level of sophistication. The actor's exploitation activities point towards financial gain and possibly nation-state interests, given the attribution to China.

Key Capabilities

  • Exploitation of CVE-2022-26134
  • 部署恶意软件如Cobalt Strike、web shells和botnets
  • 使用数字货币挖矿软件及勒索软件

MITRE ATT&CK Tactics

Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1505
T1078
T1216

Software / Tooling

Cobalt Strike
Web Shells
Botnets
Coin Miners
Ransomware Families (e.g., REvil, Conti)

Campaigns & Victims

Known for leveraging high-profile vulnerabilities, Lilac Typhoon's campaigns often involve initial access via phishing or vulnerability exploitation followed by payload deployment. Their operational tempo is characterized by targeted and lengthy campaigns focusing on data extraction, cryptojacking, or ransom activities.

IOC Patterns

  • Exploitation of CVE-2022-26134
  • Spear-phishing emails
  • C2 communication channels using web shells
  • Unusual network traffic

Recommended Actions

  • Patch Atlassian Confluence instances
  • Monitor for exploitation attempts and unusual traffic
  • Implement EDR solutions to detect malicious processes
  • Secure remote access endpoints against known payloads

Suggested Tags

APT
Financially Motivated
Ransomware
Cryptojacking
Exploitation

Confidence Assessment

The analysis is based on medium confidence due to limited available details regarding specific campaigns and exact motivations. The primary source of information is the linked software and vulnerability exploitation patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Backdoor / C2
DDoS
APT
Financially Motivated
Cryptojacking
Exploitation

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.