Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BRONZE EDGEWOOD

Also known as: Red Hariasa

Description

In early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast Asia. The threat group deployed a China Chopper webshell and ran the Nishang Invoke-PowerShellTcp.ps1 script to connect back to C2 infrastructure. The threat group is publicly linked to malware families Chinoxy, PCShare and FunnyDream. CTU researchers have discovered that BRONZE EDGEWOOD also leverages Cobalt Strike in its intrusion activity. BRONZE EDGEWOOD has been active since at least 2018 and targets government and private enterprises across Southeast Asia. CTU researchers assess with moderate confidence that BRONZE EDGEWOOD operates on behalf the Chinese government and has a remit that covers political espionage.

AI Analysis

· 2 weeks ago

Executive Summary

BRONZE EDGEWOOD, also known as Red Hariasa, is assessed as a likely state-sponsored cyber threat group linked to China. The group has been active since at least 2018, primarily targeting government and private enterprises in Southeast Asia. BRONZE EDGEWOOD's activities include deploying webshells, leveraging Cobalt Strike, and using malware families such as Chinoxy, PCShare, and FunnyDream. Their operations are suspected to focus on political espionage.

Goals & Targeting

BRONZE EDGEWOOD's primary objectives appear to be political espionage, likely on behalf of the Chinese government. The group focuses on sectors where sensitive information is held, such as government agencies and private enterprises, particularly in Southeast Asia. This suggests a strategic intent to gather intelligence that could influence regional政治 dynamics.

Enhanced Description

BRONZE EDGEWOOD is a cyber threat group observed conducting malicious activities since at least 2018. The group has demonstrated a particular interest in targeting government and private sector entities across Southeast Asia. In early 2021, CTU researchers identified the group exploiting a Microsoft Exchange Server vulnerability, deploying China Chopper webshells, and utilizing the Nishang Invoke-PowerShellTcp.ps1 script for command-and-control (C2) communication. Additionally, BRONZE EDGEWOOD is known to incorporate Cobalt Strike into its toolkit, indicating a high level of operational sophistication. The group has been linked to malware families including Chinoxy, PCShare, and FunnyDream, which are often used in campaigns targeting financial institutions and government agencies for espionage purposes.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Exploitation of Microsoft Exchange vulnerabilities
  • Webshell deployment (e.g., China Chopper)
  • Use of Cobalt Strike for C2 communication
  • Employment of Nishang scripts for remote command execution

MITRE ATT&CK Tactics

Credential Access
Execution
Exfiltration
Lateral Movement
Persistence

ATT&CK Techniques

T1059.003
T1566.001
T1078
T1055
T1048
T1218

Software / Tooling

China Chopper Webshell
Nishang Invoke-PowerShellTcp.ps1
Cobalt Strike
Chinoxy
PCShare
FunnyDream

Campaigns & Victims

BRONZE EDGEWOOD's campaigns often involve initial access through phishing or vulnerability exploitation, followed by the deployment of webshells and C2 scripts to establish persistence. The group demonstrates a patient operational tempo, focusing on long-term espionage rather than immediate damage. Notable operations include attacks against Southeast Asian government entities and financial institutions.

IOC Patterns

  • Spear-phishing emails targeting specific organizations
  • Webshell creation on compromised servers
  • C2 communication via PowerShell scripts
  • Use of known malware families (Chinoxy, PCShare, FunnyDream)

Recommended Actions

  • Implement multi-factor authentication for Exchange Server access
  • Monitor for unusual C2 activity using Process Monitor and network traffic analysis
  • Deploy endpoint detection and response solutions to detect Cobalt Strike and related tools
  • Conduct regular vulnerability assessments of email servers and web applications

Suggested Tags

APT
espionage
Southeast Asia
中国政府关联
恶意软件家族
政治间谍活动

Confidence Assessment

The assessment is based on moderate confidence due to the public linkages provided by CTU researchers. While the group's operational tactics and toolsets are well-documented, there is limited公开 attribution evidence directly linking BRONZE EDGEWOOD to Chinese government operatives.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Government Targeting
espionage
Southeast Asia
中国政府关联
恶意软件家族
政治间谍活动

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.