Also known as: Red Hariasa
In early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast Asia. The threat group deployed a China Chopper webshell and ran the Nishang Invoke-PowerShellTcp.ps1 script to connect back to C2 infrastructure. The threat group is publicly linked to malware families Chinoxy, PCShare and FunnyDream. CTU researchers have discovered that BRONZE EDGEWOOD also leverages Cobalt Strike in its intrusion activity. BRONZE EDGEWOOD has been active since at least 2018 and targets government and private enterprises across Southeast Asia. CTU researchers assess with moderate confidence that BRONZE EDGEWOOD operates on behalf the Chinese government and has a remit that covers political espionage.
Executive Summary
BRONZE EDGEWOOD, also known as Red Hariasa, is assessed as a likely state-sponsored cyber threat group linked to China. The group has been active since at least 2018, primarily targeting government and private enterprises in Southeast Asia. BRONZE EDGEWOOD's activities include deploying webshells, leveraging Cobalt Strike, and using malware families such as Chinoxy, PCShare, and FunnyDream. Their operations are suspected to focus on political espionage.
Goals & Targeting
BRONZE EDGEWOOD's primary objectives appear to be political espionage, likely on behalf of the Chinese government. The group focuses on sectors where sensitive information is held, such as government agencies and private enterprises, particularly in Southeast Asia. This suggests a strategic intent to gather intelligence that could influence regional政治 dynamics.
Enhanced Description
BRONZE EDGEWOOD is a cyber threat group observed conducting malicious activities since at least 2018. The group has demonstrated a particular interest in targeting government and private sector entities across Southeast Asia. In early 2021, CTU researchers identified the group exploiting a Microsoft Exchange Server vulnerability, deploying China Chopper webshells, and utilizing the Nishang Invoke-PowerShellTcp.ps1 script for command-and-control (C2) communication. Additionally, BRONZE EDGEWOOD is known to incorporate Cobalt Strike into its toolkit, indicating a high level of operational sophistication. The group has been linked to malware families including Chinoxy, PCShare, and FunnyDream, which are often used in campaigns targeting financial institutions and government agencies for espionage purposes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BRONZE EDGEWOOD's campaigns often involve initial access through phishing or vulnerability exploitation, followed by the deployment of webshells and C2 scripts to establish persistence. The group demonstrates a patient operational tempo, focusing on long-term espionage rather than immediate damage. Notable operations include attacks against Southeast Asian government entities and financial institutions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on moderate confidence due to the public linkages provided by CTU researchers. While the group's operational tactics and toolsets are well-documented, there is limited公开 attribution evidence directly linking BRONZE EDGEWOOD to Chinese government operatives.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics