Also known as: Mustang Panda, Earth Preta, Stately Taurus, BRONZE PRESIDENT, Bronze President, TA416, Red Delta, LuminousMoth, Twill Typhoon, Polaris, tracked as, BASIN, Red Lich, Temp.Hex, manufacturing, Storm-1789, has been targeting individuals, organizations in the software, IT, education, APT36, ProjectM, Mythic Leopard, defense, aerospace sectors using cross, BRONZE VINEWOOD, Judgment Panda, Zirconium, HoneyMyte, Greece, the Netherland, Mango Sandstorm, Tactical RMM, APT44, Strontium, Fancy Bear, Carbon Spider, Elbrus, RedDelta, Luminous Moth, ZIRCONIUM, JUDGMENT PANDA, Red keres, Violet Typhoon, TA412, TIDE CASTLE, Onyx Sleet, Earth Karkaddan, Boggy Serpens, Seashell Blizzard, Sangria Tempest
In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution involving a set of tools mentioned in the Avast report in late 2022. The incident was attributed to Camaro Dragon, a Chinese-based espionage threat actor whose activities overlap with activities tracked by different researchers as Mustang Panda and LuminousMoth, whose focus is primarily on Southeast Asian countries and their close peers.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Camaro Dragon is a Chinese-based threat actor suspected to be involved in espionage activities. Linked to Mustang Panda and LuminousMoth, Camaro Dragon focuses on Southeast Asian countries and their neighboring regions. The group has been observed targeting healthcare institutions with malware, indicating a focus on data theft or intelligence gathering.
Goals & Targeting
Camaro Dragon's strategic objectives appear to be centered on intelligence gathering and espionage, likely targeting sectors with sensitive information such as healthcare, government, and financial institutions. The group's targeting of Southeast Asian countries suggests a regional focus, possibly tied to geopolitical interests or the collection of information relevant to these regions.
Enhanced Description
Camaro Dragon is a cyber threat actor believed to be based in China, involved in espionage activities targeting primarily Southeast Asian countries and their close peers. The group's activities have been linked by researchers to Mustang Panda and LuminousMoth, suggesting possible overlaps in operations or affiliations. In early 2023, the Check Point Incident Response Team (CPIRT) investigated a malware incident at a European healthcare institution involving tools mentioned in an Avast report from late 2022. This incident was attributed to Camaro Dragon, highlighting their focus on sensitive sectors like healthcare for potential data exfiltration or espionage activities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Camaro Dragon's campaigns appear to focus on specific industries, such as healthcare, suggesting a strategic approach to target high-value information. The group's operational tempo is likely tied to their links with other Chinese-based actors, indicating potential state-sponsored activity. Notable past operations include the 2022-2023 targeting of Southeast Asian and European institutions via malware and spear-phishing attacks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the general characterization of Camaro Dragon as an espionage-focused threat actor due to its linkage with Mustang Panda and LuminousMoth. However, specific TTPs and exact modus operandi remain unclear without further data.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
44
Tools
0
Campaigns
40
IOCs
0
Observed Data
3
Tactics