Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors REF7707

Also known as: CL-STA-0049, Jewelbug, Shadow-Earth-053, Ink Dragon, tracked as, RudePanda, NosyDoor, Earth Alux

Description

REF7707, also known as CL‑STA‑0049, Jewelbug, Ink Dragon and other monikers, operates as part of a larger Chinese threat ecosystem that leverages modular loaders and distributed backdoors. The campaign’s core payload is NANOREMOTE, a FINALDRAFT variant designed for stealth persistence, lateral movement, and high‐throughput exfiltration. By exploiting legacy IIS misconfigurations—particularly ASP.NET machineKey ViewState deserialization—the actors convert victim servers into multi‑hop ShadowPad relay nodes that route command and control traffic through legitimate-looking HTTP(S) endpoints registered via the HttpAddUrl API. Initial access frequently occurs through newly disclosed SharePoint (ToolShell) vulnerabilities such as CVE‑2025‑49706, CVE‑2025‑53771 and related flaws, allowing attackers to install loaders that establish an encoded command layer delivered through victim mailboxes or local scheduled tasks. The use of Microsoft Graph API for C2 further obfuscates traffic by piggybacking on legitimate Outlook communications. The attacker’s operational pattern includes staged malware deployment, aggressive credential harvesting (including LSASS memory dumps and domain admin theft), and persistent lateral movement to achieve domain-level dominance. Although highly capable, REF7707 has exhibited poor operational security: shared infrastructure and backdoors have been exposed, providing analysts with multiple IOCs.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Education
Non profit
Media
Transportation
Maritime

Targeted Countries / Regions

CN
RU
JP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 days ago

Executive Summary

REF7707 is a Chinese‑linked espionage actor that targets government, defense and telecom entities across Europe, Southeast Asia, South America, China, Russia and Japan. It deploys a sophisticated Windows backdoor called NANOREMOTE (an evolution of FINALDRAFT) and uses compromised IIS servers as covert C2 relays through the ShadowPad IIS Listener module. The actor blends malicious traffic with legitimate Microsoft Graph API communications to evade detection while aggressively harvesting credentials for domain dominance.

Goals & Targeting

REF7707’s strategic objective is prolonged espionage of foreign policy and defense information. By infiltrating government ministries, telecom operators and public infrastructures in target countries, the actor seeks to exfiltrate privileged data such as passwords, Active Directory domain credentials, configuration files and sensitive communications. The focus on multinational adversaries—China, Russia, Japan—highlights a geopolitical imperative to support state‑level intelligence operations aligned with Chinese strategic interests.

Enhanced Description

Key Capabilities

  • Deploys a Windows backdoor called NANOREMOTE (FINALDRAFT variant) for persistence and lateral movement
  • Creates victim‑based relay networks by exploiting IIS misconfigurations such as ASP.NET machineKey ViewState deserialization via the ShadowPad IIS Listener module
  • Blends malicious traffic with legitimate Microsoft Graph API communications to evade detection
  • Utilizes staged loaders delivered through encoded command documents pushed to victim mailboxes or scheduled tasks
  • Performs aggressive credential harvesting, including LSASS dumps and domain admin theft
  • Employs wildcard HTTP(S) endpoints registered via HttpAddUrl for covert C2 channels
  • Exploits SharePoint ToolShell vulnerabilities (CVE‑2025‑49706/CVE‑2025‑53771) for initial access
  • Conducts reconnaissance of host identifiers, network adapters, installed software and system IDs

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Credential Access
Lateral Movement
Persistence
Defense Evasion
Exfiltration

ATT&CK Techniques

T1005
T1078
T1071.001
T1027
T1041
T1190
T1203
T1552.001

Software / Tooling

NANOREMOTE
FINALDRAFT
ShadowPad IIS Listener
ShadowPad
ToolShell

Campaigns & Victims

REF7707 campaigns exhibit a multi‑stage approach with rapid deployment of loaders that pivot through compromised IIS servers into a distributed relay mesh. Operational tempo is high, with new variants and exploit techniques (e.g., SharePoint CVE exploitation) introduced on a quarterly basis. Victim profiles include government ministries, defense contractors, telecom operators, education institutions and non‑profits in target countries CN, RU, JP as well as Europe, Southeast Asia and South America. Notable past operations involve the infiltration of a South American foreign ministry through a legitimate Microsoft Graph API‑based C2 channel and subsequent exfiltration of AD domain data.

IOC Patterns

  • ASP.NET machineKey ViewState deserialization exploitation
  • IIS server leveraged as a covert C2 relay node via ShadowPad IIS Listener
  • Windows backdoor deployment via NANOREMOTE
  • Vulnerability exploitation of CVE‑2025‑49706/CVE‑2025‑53771 (SharePoint) for initial access
  • Mass scanning for ToolShell vulnerability

Recommended Actions

  • Apply timely patches for IIS and SharePoint to address known machineKey misconfiguration vulnerabilities Validate and securely generate ASP.NET machineKeys on all web servers Monitor HTTP traffic for atypical command‑and‑control patterns originating from internal servers Deploy endpoint detection solutions capable of detecting NANOREMOTE behaviors (staged loaders, registry writes, network tunneling) Block or restrict communication on ports commonly used by known backdoor implants Patch all SharePoint installations against CVE‑2025‑49706, CVE‑2025‑53771, CVE‑2025‑49704 and CVE‑2025‑53770 Monitor IIS logs for unexpected HttpAddUrl API calls and wildcard URL registrations indicating ShadowPad modules Implement network segmentation and strict access controls to limit lateral movement within domain environments Employ behavioral analytics to detect unusual command‑and‑control traffic patterns and multi‑hop relay behavior Enforce least privilege policies and proactive credential monitoring to mitigate domain dominance tactics

Suggested Tags

APT
China‑aligned
Backdoor
C2 Relay
IIS Vulnerability Exploit
Windows
Government Targeting
Espionage
China State‑Sponsored
PRC‑aligned
Telecom Targeting
Public Sector Targeting
ShadowPad
ToolShell Exploit
FinalDraft Malware
Distributed Relay Network

Confidence Assessment

The analysis is based on publicly available reports from Malpedia and thehackernews, which provide consistent technical detail but lack independent verification. Confidence in identifying the actor’s tactics, techniques, capabilities and target profile is moderate; however, there are gaps regarding the exact timeline of operations, complete attribution certainty, and full inventory of IOCs.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. research.checkpoint.com — Cited by web research for: RudePanda
  2. blog.talosintelligence.com — Cited by web research for: NosyDoor
  3. www.elastic.co — Cited by web research for: PATHLOADER
  4. www.elastic.co — Cited by web research for: PowerShell

Intel Summary

8

Techniques

44

Tools

0

Campaigns

39

IOCs

0

Observed Data

7

Tactics

Tags

APT
Critical Infrastructure
Backdoor / C2
Data Exfiltration
Government Targeting
Government
Espionage
South America
China‑aligned
Backdoor
C2 Relay
IIS Vulnerability Exploit
Windows
China State‑Sponsored
PRC‑aligned
Telecom Targeting
Public Sector Targeting
ShadowPad
ToolShell Exploit
FinalDraft Malware
Distributed Relay Network

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.