Also known as: Careto, Earth Preta, Stately Taurus, Mustang Panda, ClickFix, fakeCAPTCHA
CeranaKeeper has emerged as a financially motivated threat actor with strong ties to China’s strategic objectives. Since its first activity in early 2022 the group has systematically targeted governmental institutions in Thailand, Myanmar, the Philippines, Japan, Taiwan, and Vietnam, focusing on the acquisition of sensitive political, defense, and economic data. The actors deploy a modular malware arsenal that includes custom backdoors such as TONESHELL, OneDoor, and Pubload, in addition to leveraging widely available tools like PlugX components, Bookworm, and Microsoft’s own OneDrive executable for persistence. A hallmark capability is the exploitation of legitimate cloud services for both initial command‑and‑control (C&C) and data exfiltration. CeranaKeeper engineers GitHub pull‑request and issue comment features to plant stealthy reverse shells and transform compromised hosts into covert update servers, while also using Dropbox, OneDrive, Pastebin, and PixelDrain as launch pads for malware deployment. Data staging is performed via custom staging scripts written in Batch and PowerShell that archive file trees with tools like WinRAR before encrypting payloads with AES‑128 CBC. Lateral movement often occurs through the ESET Remote Administration console or via cloud‑based C2 channels, using HTTPS traffic encrypted with proprietary symmetric keys. The group’s ability to obfuscate configuration files and masquerade legitimate library names makes signature‑based detection difficult; many indicators require behavioral or machine learning alerts to surface. In addition to government targets, CeranaKeeper (and its sibling campaigns) has extended operations toward commercial sectors such as healthcare, defense manufacturing, maritime, media, aviation, education, gaming, and think‑tanks. The actor’s adaptability is evident in the rapid deployment of new backdoors (Pubload), the use of “Paste & Run” phishing vectors, and a strategic pivot to demographic groups such as the Tibetan community through specialized campaigns.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CeranaKeeper is a China‑aligned APT active since early 2022 that targets government and critical infrastructure entities across Southeast Asia, the Japanese, Taiwanese, and Vietnamese markets. The group routinely abuses legitimate cloud platforms (e.g., Dropbox, OneDrive, GitHub) for command execution and large‑scale data exfiltration while leveraging bespoke staging tools like TONESHELL and public services such as Paste & Run to deliver malware. Its operations demonstrate a sophisticated blend of social engineering, lateral movement via ESET Remote Administration, and encrypted command-and-control channels that enable persistent, stealthy espionage campaigns.
Goals & Targeting
CeranaKeeper’s primary objective is the procurement of classified, proprietary, or otherwise sensitive data that can be monetized either through direct blackmail, market advantage, or geopolitical influence. The sectoral focus on government and defense infrastructure reflects a clear intent to undermine national security and policy formation in targeted Asian states. By pivoting between cloud‑driven delivery channels and sophisticated socialengineering techniques (Paste & Run), the actor tailors its approach to each victim’s technical posture while maintaining a low footprint that maximises persistence and data extraction efficiency.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CeranaKeeper’s campaigns exhibit a coordinated approach that begins with reconnaissance via social‑engineering phishing (Paste & Run) and continues through exploitation of cloud services to establish remote agent nodes. The group’s operational tempo saw a marked increase in 2023, aligning with the broader proliferation of China‑aligned threat actors during geopolitical tensions. Victims span multiple governmental ministries, telecom operators, healthcare facilities, and defense contractors—reflecting a broad appetite for both strategic intelligence and high-value trade secrets. Notable operations include a large data‑staging exercise leveraging Dropbox in Thailand’s Ministry of Defense and the use of GitHub API to create stealthy update servers targeting Philippine government agencies. The actor also runs subsidiary campaigns such as Stately Taurus (targeting Myanmar) and Earth Preta (focus on Tibetan community), illustrating overlapping yet distinct operational footprints. A recurring pattern is the deployment of cloud‑centric exfiltration tunnels that obfuscate traffic volumes through legitimate file‑sharing services, complicating traditional perimeter defenses. The group’s capacity to self‑host components (e.g., update servers) and pivot between tools suggests a modular architecture with rapid rebuild capabilities when faced with defensive countermeasures. Overall, CeranaKeeper operates as a high‑profile espionage actor that prioritizes stealth, data volume, and financial exploitation across political and commercial sectors in the Indo‑Pacific region.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly available reports and shared threat‑intel repositories; attribution to the group is supported by consistent naming, infrastructure usage, and observable tactics. However, gaps remain in exact asset inventory, the full scope of affected sectors outside governmental bodies, and precise financial motives beyond reported data theft patterns. Continuous monitoring of new indicators will be required to refine threat actor profiles and validate ongoing operational intentions.
No campaigns linked yet.
No observed data linked yet.
26
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
9
Tactics