Operation Wocao (我操, “Wǒ cāo”, used as “shit” or “damn”) is the name that Fox-IT uses to describe the hacking activities of a Chinese based hacking group. This report details the profile of a publicly underreported threat actor that Fox-IT has dealt with over the past two years. Fox-IT assesses with high confidence that the actor is a Chinese group and that they are likely working to support the interests of the Chinese government and are tasked with obtaining information for espionage purposes. With medium confidence, Fox-IT assesses that the tools, techniques and procedures are those of the actor referred to as APT20 by industry partners. We have identified victims of this actor in more than 10 countries, in government entities, managed service providers and across a wide variety of industries, including Energy, Health Care and High-Tech.
Executive Summary
Operation Wocao (我操), described by Fox-IT as a Chinese-based hacking group, is assessed with high confidence to be involved in espionage activities targeting government entities and critical sectors globally. The group's operations suggest alignment with state-sponsored objectives, likely supporting the interests of the Chinese government.
Goals & Targeting
Operation Wocao appears to operate with strategic objectives centered on intelligence gathering for espionage purposes, likely supporting Chinese government interests. The group targets a diverse range of sectors, including energy, healthcare, high-tech industries, and government entities, indicating a focus on extracting sensitive information that could provide competitive or geopolitical advantages.
Enhanced Description
Operation Wocao has been observed by Fox-IT over the past two years as a persistent threat actor with suspected ties to APT20, though this link is assessed with medium confidence. The group primarily engages in cyber espionage activities aimed at gathering sensitive information from multiple sectors, including government, healthcare, energy, and high-tech industries. Victims have been identified across more than 10 countries, underscoring a global targeting scope. While specific details on the group's TTPs are limited, they likely employ sophisticated techniques to infiltrate targets and exfiltrate data.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operation Wocao has demonstrated a prolonged operational timeline, targeting multiple countries and sectors. Their campaigns likely involve long-term access to victim networks for data collection. Notable for their stealth and persistence, the group appears capable of maintaining presence in highly secured environments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence exists in the assessment that Wocao is a Chinese-based group with espionage objectives. However, specific details about their tools and techniques remain somewhat speculative due to limited公开 reporting.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics