Also known as: Careto, Synaptics worm
IcePeony, also known by aliases Careto and Synaptics worm, is a sophisticated threat actor that emerged in 2023‑24. Based on open‑source reports from Broadcom’s security bulletin and Malpedia, the group focuses on institutions in India, Mauritius, Vietnam, China, North Korea, Poland, Pakistan and Indonesia – roughly speaking, governments and organizations whose data could support Chinese national objectives, especially maritime strategy. The group’s campaign tactics revolve around low‑hanging technical fruit. They leverage SQL injection against publicly exposed web applications to gain initial access, then install a variety of web shells or custom malware such as IceCache for persistence and lateral movement. In addition to credential theft, they use Microsoft’s Windows Management Instrumentation (WMI) and PowerShell scripts (T1059/T1059.001) to execute commands on compromised hosts, and often obfuscate their payloads using techniques described in T1027. IcePeony also demonstrates an awareness of defensive tooling: it employs email‑hiding rules (T1564.008), sets up forwarding rules, and may use cloud accounts for staging or command and control (T1078.004). Their toolset overlaps with well‑known RATs such as Avaddon, AnyDesk, TeamViewer, MeshCentral, and several lesser‑known utilities (Rhadamanthys, MintsLoader, Hook, Nexus). Collectively, these capabilities allow the actor to establish persistence, move laterally within networks, exfiltrate data, and remain stealthy over extended periods. Operationally, IcePeony appears to run under a heavy work schedule (the 996 system), with consistent pressure to deliver financial gains while advancing state objectives. While specific attribution remains difficult, the correlation of their TTPs with China‑state strategic interests suggests a possible alignment or support from Chinese state cyber units. Overall, IcePeony represents a hybrid threat: financially motivated, yet capable of executing politically relevant espionage against key Southeast Asian actors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
IcePeony is a China‑linked APT group that has been active since at least early 2024, targeting governments, universities and critical infrastructure across Southeast Asia and the Indian Ocean region. The operators primarily exploit SQL injection vulnerabilities on public web servers to drop web shells or deploy custom malware such as IceCache for credential theft. Their operations appear financially motivated yet aligned with broader Chinese strategic interests in maritime and regional governance.
Goals & Targeting
IcePeony’s strategic objectives seem dual‑purpose. Primarily, the group seeks financial gain through credential theft and exploitation of vulnerabilities to monetize access or sell stolen data. Concurrently, they target government bodies, critical infrastructure and educational institutions within India, South Asia, and nearby island nations that are vital to China’s maritime and geopolitical ambitions. By compromising these sectors, the actors can gather sensitive policy and logistical information beneficial to Chinese naval interests, while also potentially disrupting their adversaries’ domestic stability.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
IcePeony appears to conduct campaigns in a systematic, low‑cost manner. The group initiates attacks via publicly known web application flaws (mainly SQL injection), deploys lightweight web shells or custom ransomware families, and uses a mix of legitimate remote desktop tools for lateral movement. Their operations target public sector entities within India, Southeast Asia and adjacent island nations on an annual basis, with a focus on critical infrastructure such as telecommunications, energy and defense. A pattern emerges in their preference for leveraging commercial VPN or remote access software (e.g., AnyDesk, TeamViewer) to maintain persistence, which suggests a blend of opportunistic hacking and organized intrusion workflows.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The core existence and geographic focus of IcePeony are strongly supported by Broadcom’s security bulletin (Oct 2024) and corroborated by Malpedia entries for associated malware families. Specific tactics such as SQL injection, web shell deployment, and use of PowerShell are derived from the same sources. However, details about internal organizational structure, precise financial impact metrics, or a full list of exploited CVEs remain incomplete; many technique references come from tied ATT&CK IDs rather than explicit incident reports, creating information gaps. Confidence is medium‑high for operational profile but lower for technical nuance (e.g., exact C2 protocol choices).
No campaigns linked yet.
No observed data linked yet.
10
Techniques
41
Tools
0
Campaigns
19
IOCs
0
Observed Data
4
Tactics