Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors IcePeony

Also known as: Careto, Synaptics worm

Description

IcePeony, also known by aliases Careto and Synaptics worm, is a sophisticated threat actor that emerged in 2023‑24. Based on open‑source reports from Broadcom’s security bulletin and Malpedia, the group focuses on institutions in India, Mauritius, Vietnam, China, North Korea, Poland, Pakistan and Indonesia – roughly speaking, governments and organizations whose data could support Chinese national objectives, especially maritime strategy. The group’s campaign tactics revolve around low‑hanging technical fruit. They leverage SQL injection against publicly exposed web applications to gain initial access, then install a variety of web shells or custom malware such as IceCache for persistence and lateral movement. In addition to credential theft, they use Microsoft’s Windows Management Instrumentation (WMI) and PowerShell scripts (T1059/T1059.001) to execute commands on compromised hosts, and often obfuscate their payloads using techniques described in T1027. IcePeony also demonstrates an awareness of defensive tooling: it employs email‑hiding rules (T1564.008), sets up forwarding rules, and may use cloud accounts for staging or command and control (T1078.004). Their toolset overlaps with well‑known RATs such as Avaddon, AnyDesk, TeamViewer, MeshCentral, and several lesser‑known utilities (Rhadamanthys, MintsLoader, Hook, Nexus). Collectively, these capabilities allow the actor to establish persistence, move laterally within networks, exfiltrate data, and remain stealthy over extended periods. Operationally, IcePeony appears to run under a heavy work schedule (the 996 system), with consistent pressure to deliver financial gains while advancing state objectives. While specific attribution remains difficult, the correlation of their TTPs with China‑state strategic interests suggests a possible alignment or support from Chinese state cyber units. Overall, IcePeony represents a hybrid threat: financially motivated, yet capable of executing politically relevant espionage against key Southeast Asian actors.

Goals & Targeting

Targeted Sectors

Government
Defense
Education
Financial services
Telecommunications
Critical infrastructure
Manufacturing
Energy
Media

Targeted Countries / Regions

CN
KP
PL
PK
IN

AI Analysis

Grounded in web research
· 2 hours ago

Executive Summary

IcePeony is a China‑linked APT group that has been active since at least early 2024, targeting governments, universities and critical infrastructure across Southeast Asia and the Indian Ocean region. The operators primarily exploit SQL injection vulnerabilities on public web servers to drop web shells or deploy custom malware such as IceCache for credential theft. Their operations appear financially motivated yet aligned with broader Chinese strategic interests in maritime and regional governance.

Goals & Targeting

IcePeony’s strategic objectives seem dual‑purpose. Primarily, the group seeks financial gain through credential theft and exploitation of vulnerabilities to monetize access or sell stolen data. Concurrently, they target government bodies, critical infrastructure and educational institutions within India, South Asia, and nearby island nations that are vital to China’s maritime and geopolitical ambitions. By compromising these sectors, the actors can gather sensitive policy and logistical information beneficial to Chinese naval interests, while also potentially disrupting their adversaries’ domestic stability.

Enhanced Description

Key Capabilities

  • SQL injection exploitation of public web servers
  • Deployment of web shells for persistence and lateral movement
  • Custom malware deployment (IceCache) for credential theft
  • Use of Windows Management Instrumentation for remote execution
  • PowerShell scripting for command and control
  • Obfuscated payload delivery (T1027)
  • Email hiding and forwarding rules to evade detection (T1564.008, T1114.003)
  • Ingress tool transfer via T1105
  • Cloud account usage for staging or C2 (T1078.004)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1047
T1564.008
T1530
T1059
T1114.003
T1059.001
T1027
T1204.004
T1105
T1078.004

Software / Tooling

Avaddon
SocGholish
netsh
ConnectWise
Quick Assist
Phyishing
Hunter
PowerShell
Rhadamanthys
Matrix
Netsupport Manager
AnyDesk
Hook
Nexus
KongTuke
MintsLoader
Careto
Interception
Leverage
systemd
Custom malware
Global
STOP
Process Hollowing
MeshCentral
AppDomainManager
Group Policy
Windows Command Shell
LummaC2
TeamViewer
MESHAGENT
Remote access tools
BITS
mshta
SimpleHelp
Fleetdeck
MSBuild

Campaigns & Victims

IcePeony appears to conduct campaigns in a systematic, low‑cost manner. The group initiates attacks via publicly known web application flaws (mainly SQL injection), deploys lightweight web shells or custom ransomware families, and uses a mix of legitimate remote desktop tools for lateral movement. Their operations target public sector entities within India, Southeast Asia and adjacent island nations on an annual basis, with a focus on critical infrastructure such as telecommunications, energy and defense. A pattern emerges in their preference for leveraging commercial VPN or remote access software (e.g., AnyDesk, TeamViewer) to maintain persistence, which suggests a blend of opportunistic hacking and organized intrusion workflows.

IOC Patterns

  • SQL injection on publicly exposed web applications
  • Web shell installation on compromised servers
  • Deployment of IceCache custom RAT
  • Use of mshta.exe for payload execution
  • Remote desktop tool usage (AnyDesk, TeamViewer, MeshCentral)
  • C2 communication over custom or fast‑flux domains
  • Email forwarding and hiding rules to obfuscate traffic

Recommended Actions

  • Implement comprehensive input validation and WAFs on all public web interfaces to mitigate SQL injection.
  • Regularly audit and patch public‑facing applications for known CVEs.
  • Monitor host files and registry changes indicative of web shell placement or mshta usage.
  • Deploy behavioral analytics to detect anomalous PowerShell executions and WMI calls.
  • Restrict remote desktop tool access to approved devices and monitor for unusual lateral movements.
  • Enhance logging of email forwarding rules to detect stealthy mail‑to‑mail chains.
  • Adopt multi‑factor authentication and least privilege models, especially on administrative accounts that could be targeted via credential theft.

Suggested Tags

APT
China-nexus
Financial gain
Government targeting
Education sector
Critical infrastructure
Maritime strategy
Web shell exploitation

Confidence Assessment

The core existence and geographic focus of IcePeony are strongly supported by Broadcom’s security bulletin (Oct 2024) and corroborated by Malpedia entries for associated malware families. Specific tactics such as SQL injection, web shell deployment, and use of PowerShell are derived from the same sources. However, details about internal organizational structure, precise financial impact metrics, or a full list of exploited CVEs remain incomplete; many technique references come from tied ATT&CK IDs rather than explicit incident reports, creating information gaps. Confidence is medium‑high for operational profile but lower for technical nuance (e.g., exact C2 protocol choices).

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. redcanary.com — Cited by web research for: T1078.004
  2. attack.mitre.org — Cited by web research for: Interception
  3. unit42.paloaltonetworks.com — Cited by web research for: TeamViewer
  4. https://www.broadcom.com/support/security-center/protection-bulletin/icepeony-china-linked-apt-group-targeting-southeast-asian-governments — Cited by AI analysis.
  5. https://malpedia.caad.fkie.fraunhofer.de/details/win.avaddon — Cited by AI analysis.

Intel Summary

10

Techniques

41

Tools

0

Campaigns

19

IOCs

0

Observed Data

4

Tactics

Tags

APT
Backdoor / C2
Data Exfiltration
Government Targeting
espionage
China-linked
government-sector
India
Vietnam
Maritime Strategy
Web Exploitation
China-nexus
Financial gain
Government targeting
Education sector
Critical infrastructure
Maritime strategy
Web shell exploitation

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.