Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BRONZE VAPOR

Description

BRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin. Artefacts from tools associated with this group and open source reporting on related incidents indicate that BRONZE VAPOR have operated since at least 2017. The group conducts espionage against multiple industries including semiconductors, aviation and telecommunications. CTU researchers assess BRONZE VAPOR's intent to be information theft, with operations focused on intellectual property (semiconductors) and personally identifiable information such as traveller records (aviation). Compromise of telecommunications companies can yield personally identifiable information and meta data on client communications such as Call Data Records (CDR). Prior to 2019 their operational focus, with some exceptions, revolved around targets in East Asia particularity Taiwan with it's thriving semiconductor industry. In 2021 details emerged in open source of attacks on at least one European semiconductor company believed to date back to 2017. In 2019 BRONZE VAPOR attacked one of more entities in the European airlines sector. The group gains initial access via VPN services, may use spearphishing with 'Letter of Appointment' themed lures, and deploys Cobalt Strike along with custom data exfiltration tools to target organizations. Post-intrusion activity involves living-of-the-land using legitimate tools and commands available within victim environment as well as using AceHash for credential harvesting, WATERCYCLE for data exfiltration and STOCKPIPE for proxying information through Microsoft Exchange servers over email. BRONZE VAPOR uses a set of tactics that, although not individually unique, when viewed in aggregate create a relatively distinct playbook. Intrusions begin with credential based attacks against an existing remote access solution (Citrix, VPN etc.) or B2B network access. Cobalt Strike is deployed into the environment and further access is then conducted via Cobalt Strike Beacon and other features of the platform. Sharphound is deployed to map out the victim's Active Directory infrastructure and and collect critical information about the domain including important account names. Command and control infrastructure is hosted on subdomains of Azure and Appspot services to blend in with legitimate traffic. The threat actor also registers their own domains for command and control, often with a "sync" or "update" related theme. WinRAR is commonly used for compressing data prior to exfiltration. Filenames for these archives often involve a string of numbers and variations of the word "update". Data is exfiltrated using WATERCYCLE to cloud based platforms such as OneDrive and GoogleDrive.

AI Analysis

· 1 week ago

Executive Summary

BRONZE VAPOR is a Chinese-origin threat group targeting sectors like semiconductors and aviation for espionage, using tools such as Cobalt Strike and WATERCYCLE to steal intellectual property and personal data. Their operations span East Asia and Europe, posing significant risks to organizations in these industries.

Goals & Targeting

BRONZE VAPOR targets sectors like semiconductors for intellectual property theft, aviation for personally identifiable information (PII), and telecommunications for metadata. Their strategic objectives involve espionage to gather sensitive information for potential national or economic advantage. They initially focused on East Asia, particularly Taiwan, due to its semiconductor industry, but expanded to Europe in 2019 and beyond.

Enhanced Description

BRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin. Operating since at least 2017, they conduct espionage against multiple industries including semiconductors, aviation, and telecommunications. Their goal appears to be information theft, focusing on intellectual property (semiconductors) and personally identifiable information such as traveler records (aviation). They compromise telecommunications companies to obtain PII and metadata like Call Data Records (CDR). BRONZE VAPOR's tactics include initial access via VPN services, spearphishing with 'Letter of Appointment' themed lures, deployment of Cobalt Strike, AceHash for credential harvesting, WATERCYCLE for data exfiltration, and STOCKPIPE for proxying information through Microsoft Exchange servers. Their command and control infrastructure uses subdomains of Azure and Appspot services, often registering domains with themes like 'sync' or 'update'. Data is exfiltrated using legitimate cloud platforms such as OneDrive and Google Drive.

Key Capabilities

  • Credential harvesting via AceHash
  • Data exfiltration using WATERCYCLE and STOCKPIPE
  • Cobalt Strike for initial access
  • Sharphound for Active Directory infrastructure mapping
  • WinRAR for file compression with 'update' themed filenames
  • Cloud storage abuse (OneDrive, Google Drive)
  • Command and control via Azure and Appspot subdomains

MITRE ATT&CK Tactics

Initial Access
Execution
Discovery
Exfiltration

ATT&CK Techniques

T1059
T1078
T1048
T1065
T1576
T1485

Software / Tooling

Cobalt Strike
AceHash
WATERCYCLE
STOCKPIPE
Sharphound
WinRAR

Campaigns & Victims

BRONZE VAPOR's campaigns show a focus on semiconductors, airlines, and telecommunications. Their tactics involve compromising VPN services or B2B network access to gain initial entry. They use legitimate tools within the environment, such as WinRAR for data compression, and exfiltrate data through cloud platforms like OneDrive and Google Drive. Notable operations include attacks on a European semiconductor company since 2017 and airline sector targets in 2019.

IOC Patterns

  • Spear-phishing emails with 'Letter of Appointment' themes
  • Deployment of Cobalt Strike Beacon
  • Use of custom data exfiltration tools like WATERCYCLE
  • Registry for domains related to 'sync' or 'update'
  • VPN service compromises

Recommended Actions

  • Harden remote access points such as VPNs with multi-factor authentication
  • Monitor网络 traffic for signs of Cobalt Strike activity
  • Implement robust cloud security measures and logging
  • Block domains registered under 'sync' or 'update' themes
  • Use network monitoring tools to detect unusual data exfiltration

Suggested Tags

APT
Espionage
Semiconductors
Aviation
China

Confidence Assessment

Moderate confidence in BRONZE VAPOR's Chinese origin and espionage activities. Data gaps include exact origins, full scope beyond known campaigns, detailed TTPs, and precise impact assessment.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Data Exfiltration
Espionage
Semiconductors
Aviation
China

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.