Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CeranaKeeper

Also known as: Careto, Earth Preta, Stately Taurus, Mustang Panda, ClickFix, fakeCAPTCHA

Description

CeranaKeeper has emerged as a financially motivated threat actor with strong ties to China’s strategic objectives. Since its first activity in early 2022 the group has systematically targeted governmental institutions in Thailand, Myanmar, the Philippines, Japan, Taiwan, and Vietnam, focusing on the acquisition of sensitive political, defense, and economic data. The actors deploy a modular malware arsenal that includes custom backdoors such as TONESHELL, OneDoor, and Pubload, in addition to leveraging widely available tools like PlugX components, Bookworm, and Microsoft’s own OneDrive executable for persistence. A hallmark capability is the exploitation of legitimate cloud services for both initial command‑and‑control (C&C) and data exfiltration. CeranaKeeper engineers GitHub pull‑request and issue comment features to plant stealthy reverse shells and transform compromised hosts into covert update servers, while also using Dropbox, OneDrive, Pastebin, and PixelDrain as launch pads for malware deployment. Data staging is performed via custom staging scripts written in Batch and PowerShell that archive file trees with tools like WinRAR before encrypting payloads with AES‑128 CBC. Lateral movement often occurs through the ESET Remote Administration console or via cloud‑based C2 channels, using HTTPS traffic encrypted with proprietary symmetric keys. The group’s ability to obfuscate configuration files and masquerade legitimate library names makes signature‑based detection difficult; many indicators require behavioral or machine learning alerts to surface. In addition to government targets, CeranaKeeper (and its sibling campaigns) has extended operations toward commercial sectors such as healthcare, defense manufacturing, maritime, media, aviation, education, gaming, and think‑tanks. The actor’s adaptability is evident in the rapid deployment of new backdoors (Pubload), the use of “Paste & Run” phishing vectors, and a strategic pivot to demographic groups such as the Tibetan community through specialized campaigns.

Goals & Targeting

Targeted Sectors

Government
Non profit
Healthcare
Manufacturing
Think tank
Telecommunications
Defense
Maritime
Media
Aviation
Education
Gaming

Targeted Countries / Regions

CN
JP
TW
VN
AU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 8 hours ago

Executive Summary

CeranaKeeper is a China‑aligned APT active since early 2022 that targets government and critical infrastructure entities across Southeast Asia, the Japanese, Taiwanese, and Vietnamese markets. The group routinely abuses legitimate cloud platforms (e.g., Dropbox, OneDrive, GitHub) for command execution and large‑scale data exfiltration while leveraging bespoke staging tools like TONESHELL and public services such as Paste & Run to deliver malware. Its operations demonstrate a sophisticated blend of social engineering, lateral movement via ESET Remote Administration, and encrypted command-and-control channels that enable persistent, stealthy espionage campaigns.

Goals & Targeting

CeranaKeeper’s primary objective is the procurement of classified, proprietary, or otherwise sensitive data that can be monetized either through direct blackmail, market advantage, or geopolitical influence. The sectoral focus on government and defense infrastructure reflects a clear intent to undermine national security and policy formation in targeted Asian states. By pivoting between cloud‑driven delivery channels and sophisticated social­engineering techniques (Paste & Run), the actor tailors its approach to each victim’s technical posture while maintaining a low footprint that maximises persistence and data extraction efficiency.

Enhanced Description

Key Capabilities

  • Hosted compromised machines as update servers
  • Created stealthy reverse shells via GitHub pull request and issue comment features
  • Used single‑use harvesting components for full file tree collection
  • Abused legitimate cloud storage (Dropbox, OneDrive, Pastebin, GitHub, PixelDrain) for command execution and data exfiltration
  • Massive data exfiltration from targeted governmental institutions
  • Employs custom staging toolset (TONESHELL) for delivery
  • Uses side‑loading technique for initial access
  • Executes predefined command sequences for file exfiltration
  • Leverages ESET Remote Administration console for lateral movement
  • Encrypts configuration files using AES‑128 CBC
  • Masquerades with legitimate library names
  • Acquires and uses domains, VPS servers, and cloud accounts

MITRE ATT&CK Tactics

Defense Evasion
Collection
Exfiltration
Command and Control
Resource Development
Execution

ATT&CK Techniques

T1036.005
T1560.001
T1583.001
T1583.003
T1587.001
T1585.003
T1072
T1140
T1071.001
T1573.001
T1566.002
T1106
T1005
T1090.001
T1547.001
T1039
T1102.002
T1573.002
T1567.002
T1132.002
T1204.002
T1204
T1204.004
T1574.002

Software / Tooling

TONESHELL
OneDoor backdoor
Pubload backdoor
ClickFix/fakeCAPTCHA
PlugX components
Bookworm
Cobalt Strike
DOPLUGS
GRAYRABBIT
Hodur
MQsTTang
WavyExfiller
Microsoft OneDrive executable

Campaigns & Victims

CeranaKeeper’s campaigns exhibit a coordinated approach that begins with reconnaissance via social‑engineering phishing (Paste & Run) and continues through exploitation of cloud services to establish remote agent nodes. The group’s operational tempo saw a marked increase in 2023, aligning with the broader proliferation of China‑aligned threat actors during geopolitical tensions. Victims span multiple governmental ministries, telecom operators, healthcare facilities, and defense contractors—reflecting a broad appetite for both strategic intelligence and high-value trade secrets. Notable operations include a large data‑staging exercise leveraging Dropbox in Thailand’s Ministry of Defense and the use of GitHub API to create stealthy update servers targeting Philippine government agencies. The actor also runs subsidiary campaigns such as Stately Taurus (targeting Myanmar) and Earth Preta (focus on Tibetan community), illustrating overlapping yet distinct operational footprints. A recurring pattern is the deployment of cloud‑centric exfiltration tunnels that obfuscate traffic volumes through legitimate file‑sharing services, complicating traditional perimeter defenses. The group’s capacity to self‑host components (e.g., update servers) and pivot between tools suggests a modular architecture with rapid rebuild capabilities when faced with defensive countermeasures. Overall, CeranaKeeper operates as a high‑profile espionage actor that prioritizes stealth, data volume, and financial exploitation across political and commercial sectors in the Indo‑Pacific region.

IOC Patterns

  • "bectrl" string used in code
  • GitHub pull‑request/issue comment reverse shell technique
  • Use of Dropbox, OneDrive, Pastebin, GitHub for command execution and exfiltration
  • Domain registration and usage for attacker infrastructure
  • VPS server deployment
  • Encrypted configuration files (AES‑128 CBC)
  • Masquerading legitimate library names
  • HTTPS C2 traffic using AES encryption
  • .lnk shortcut files as phishing delivery
  • RAR archives attaching malware payloads
  • Geopolitical targeting of Philippines, Myanmar, Thailand
  • Demographic focus on Tibetan community
  • ESET Remote Administration console usage for lateral movement
  • Cloud account abuse via OneDrive and GitHub

Recommended Actions

  • Monitor and restrict use of legitimate cloud‑based file sharing services (Dropbox, OneDrive, Pastebin) to detect and block unauthorized data exfiltration
  • Detect and alert on anomalous usage of GitHub API pull requests or issue comments that indicate hidden reverse shells
  • Implement application whitelisting and code integrity checks to mitigate masquerading and obfuscated payloads
  • Track domain registrations and VPS provisioning linked to known attacker infrastructure, and block traffic from newly registered domains
  • Block lateral movement through external remote administration consoles (e.g., ESET Remote Administrator) unless explicitly authorized
  • Enforce strict encryption policy compliance; monitor for AES‑128 CBC traffic that does not match legitimate application patterns
  • Deploy endpoint detection and response to detect Bookworm, Pubload, and other custom backdoors via file hash or behavioral indicators
  • Configure email filtering to block suspicious .lnk and RAR attachments commonly used in Paste & Run phishing
  • Provide targeted user training on social engineering vectors such as

Suggested Tags

APT
China‑aligned
Financial Gain
Government Target
Non-Profit
Healthcare
Manufacturing
Think‑tank
Telecom
Defense
Maritime
Media
Aviation
Education
Gaming
Data Exfiltration
Cloud Service Abuse
Masquerading
GitHub C2 Abuse
Staging Tool
Side‑loading Initial Access
Command and Control over HTTPS
Encrypted C2
Virtual Private Server
Public Cloud Accounts
Backdoor Deployment
Phishing (Paste & Run)
Bookworm Malware
Pubload Backdoor
ClickFix
fakeCAPTCHA
TONESHELL
OneDoor","ESET Remote Administration

Confidence Assessment

The analysis is based on publicly available reports and shared threat‑intel repositories; attribution to the group is supported by consistent naming, infrastructure usage, and observable tactics. However, gaps remain in exact asset inventory, the full scope of affected sectors outside governmental bodies, and precise financial motives beyond reported data theft patterns. Continuous monitoring of new indicators will be required to refine threat actor profiles and validate ongoing operational intentions.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 12 IPv4 Address 2 Filename 3 SHA-256 Hash 3

References

  1. www.welivesecurity.com — Cited by web research for: Earth Preta
  2. apt.etda.or.th — Cited by web research for: Mustang Panda
  3. attack.mitre.org — Cited by web research for: ClickFix
  4. www.eset.com — Cited by web research for: Expand
  5. apt.etda.or.th — Cited by web research for: Japan
  6. https://www.eset.com/us/about/newsroom/press-releases/eset-research-discovers-new-china-aligned-apt-group-ceranakeeper- — Cited by AI analysis.
  7. https://www.eset.com/us/business/services/apt-reports/?srsltid=AfmBOopEbqjworLQW5V6J_o_RPHI63eQI4QfNn-_H0pQS9epWK1MAce — Cited by AI analysis.
  8. https://blog.google/threat-analysis-group/update-threat-landscape-ukraine/ — Cited by AI analysis.
  9. https://blog.talosintelligence.com/2022/05/mustang-panda-targets-europe.html — Cited by AI analysis.
  10. https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets — Cited by AI analysis.
  11. https://www.trendmicro.com/en_us/research/22/k/earth-preta-spear-phishing-governments-worldwide.html — Cited by AI analysis.
  12. https://www.trendmicro.com/en_us/research/23/c/earth-preta-cyberespionage-campaign-hits-over-200.html — Cited by AI analysis.
  13. https://welivesecurity.com/2023/03/02/mqsttang-mustang-panda-latest-backdoor-treads-new-ground-qt-mqtt/ — Cited by AI analysis.
  14. https://unit42.paloaltonetworks.com/stately-taurus-targets-philippines-government-cyberespionage/ — Cited by AI analysis.
  15. https://csirt-cti.net/2024/01/23/stately-taurus-targets-myanmar/ — Cited by AI analysis.
  16. https://unit42.paloaltonetworks.com/stately-taurus-uses-bookworm-malware/ — Cited by AI analysis.
  17. https://www.ibm.com/think/x-force/hive0154-mustang-panda-shifts-focus-tibetan-community-deploy-pubload-backdoor — Cited by AI analysis.

Intel Summary

26

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

9

Tactics

Tags

APT
Backdoor / C2
Data Exfiltration
Government Targeting
Cyber Espionage
China-Linked
Government Sector
Asia Region Focus
China‑aligned
Financial Gain
Government Target
Non-Profit
Healthcare
Manufacturing
Think‑tank
Telecom
Defense
Maritime
Media
Aviation
Education
Gaming
Cloud Service Abuse
Masquerading
GitHub C2 Abuse
Staging Tool
Side‑loading Initial Access
Command and Control over HTTPS
Encrypted C2
Virtual Private Server
Public Cloud Accounts
Backdoor Deployment
Phishing (Paste & Run)
Bookworm Malware
Pubload Backdoor
ClickFix
fakeCAPTCHA
TONESHELL
OneDoor","ESET Remote Administration

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.