Also known as: CL-STA-0049, Jewelbug, Shadow-Earth-053, Ink Dragon, tracked as, RudePanda, NosyDoor, Earth Alux
REF7707, also known as CL‑STA‑0049, Jewelbug, Ink Dragon and other monikers, operates as part of a larger Chinese threat ecosystem that leverages modular loaders and distributed backdoors. The campaign’s core payload is NANOREMOTE, a FINALDRAFT variant designed for stealth persistence, lateral movement, and high‐throughput exfiltration. By exploiting legacy IIS misconfigurations—particularly ASP.NET machineKey ViewState deserialization—the actors convert victim servers into multi‑hop ShadowPad relay nodes that route command and control traffic through legitimate-looking HTTP(S) endpoints registered via the HttpAddUrl API. Initial access frequently occurs through newly disclosed SharePoint (ToolShell) vulnerabilities such as CVE‑2025‑49706, CVE‑2025‑53771 and related flaws, allowing attackers to install loaders that establish an encoded command layer delivered through victim mailboxes or local scheduled tasks. The use of Microsoft Graph API for C2 further obfuscates traffic by piggybacking on legitimate Outlook communications. The attacker’s operational pattern includes staged malware deployment, aggressive credential harvesting (including LSASS memory dumps and domain admin theft), and persistent lateral movement to achieve domain-level dominance. Although highly capable, REF7707 has exhibited poor operational security: shared infrastructure and backdoors have been exposed, providing analysts with multiple IOCs.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
REF7707 is a Chinese‑linked espionage actor that targets government, defense and telecom entities across Europe, Southeast Asia, South America, China, Russia and Japan. It deploys a sophisticated Windows backdoor called NANOREMOTE (an evolution of FINALDRAFT) and uses compromised IIS servers as covert C2 relays through the ShadowPad IIS Listener module. The actor blends malicious traffic with legitimate Microsoft Graph API communications to evade detection while aggressively harvesting credentials for domain dominance.
Goals & Targeting
REF7707’s strategic objective is prolonged espionage of foreign policy and defense information. By infiltrating government ministries, telecom operators and public infrastructures in target countries, the actor seeks to exfiltrate privileged data such as passwords, Active Directory domain credentials, configuration files and sensitive communications. The focus on multinational adversaries—China, Russia, Japan—highlights a geopolitical imperative to support state‑level intelligence operations aligned with Chinese strategic interests.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
REF7707 campaigns exhibit a multi‑stage approach with rapid deployment of loaders that pivot through compromised IIS servers into a distributed relay mesh. Operational tempo is high, with new variants and exploit techniques (e.g., SharePoint CVE exploitation) introduced on a quarterly basis. Victim profiles include government ministries, defense contractors, telecom operators, education institutions and non‑profits in target countries CN, RU, JP as well as Europe, Southeast Asia and South America. Notable past operations involve the infiltration of a South American foreign ministry through a legitimate Microsoft Graph API‑based C2 channel and subsequent exfiltration of AD domain data.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly available reports from Malpedia and thehackernews, which provide consistent technical detail but lack independent verification. Confidence in identifying the actor’s tactics, techniques, capabilities and target profile is moderate; however, there are gaps regarding the exact timeline of operations, complete attribution certainty, and full inventory of IOCs.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
44
Tools
0
Campaigns
39
IOCs
0
Observed Data
7
Tactics