CardinalLizard, a cyber threat actor linked to China, has targeted entities in Asia since 2018. Their methods include spear-phishing, custom malware with anti-detection features, and potentially shared infrastructure with other actors.
Executive Summary
CardinalLizard is a cyber threat actor linked to China, primarily active since 2018, targeting entities in Asia. Known for sophisticated attacks involving spear-phishing and custom malware with anti-detection features, CardinalLizard poses a significant threat to organizations in their targeted sectors.
Goals & Targeting
CardinalLizard's strategic objectives appear to include intelligence collection and espionage against critical infrastructure in Asia. Their targeting of sectors like energy and telecommunications suggests a focus on gaining access to sensitive information and disrupting operations. Typical victims are government entities, private sector organizations, and those operating within China's geopolitical interests.
Enhanced Description
CardinalLizard is a state-sponsored cyber threat group associated with China, first observed in 2018. Their primary activity involves targeting Asian entities, particularly in the energy and telecommunications sectors. The group employs advanced tactics such as spear-phishing campaigns, deployment of custom malware with anti-detection mechanisms, and potential operational sharing with other actors. CardinalLizard's attacks are designed to achieve long-term persistence and data exfiltration, aligning with broader Chinese state interests.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CardinalLizard's campaigns demonstrate a focus on stealth and long-term access. They have targeted organizations in Asia since 2018, with notable operations involving energy and telecommunications sectors. Their use of custom malware indicates a high level of sophistication. No specific campaigns are publicly documented beyond their general targeting patterns.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in CardinalLizard's existence, goals, and capabilities based on public reporting. Limited details on specific campaigns and techniques used outside of general TTPs. No direct attribution to concrete incidents beyond the sectors targeted.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics