BRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin. Artefacts from tools associated with this group and open source reporting on related incidents indicate that BRONZE VAPOR have operated since at least 2017. The group conducts espionage against multiple industries including semiconductors, aviation and telecommunications. CTU researchers assess BRONZE VAPOR's intent to be information theft, with operations focused on intellectual property (semiconductors) and personally identifiable information such as traveller records (aviation). Compromise of telecommunications companies can yield personally identifiable information and meta data on client communications such as Call Data Records (CDR). Prior to 2019 their operational focus, with some exceptions, revolved around targets in East Asia particularity Taiwan with it's thriving semiconductor industry. In 2021 details emerged in open source of attacks on at least one European semiconductor company believed to date back to 2017. In 2019 BRONZE VAPOR attacked one of more entities in the European airlines sector. The group gains initial access via VPN services, may use spearphishing with 'Letter of Appointment' themed lures, and deploys Cobalt Strike along with custom data exfiltration tools to target organizations. Post-intrusion activity involves living-of-the-land using legitimate tools and commands available within victim environment as well as using AceHash for credential harvesting, WATERCYCLE for data exfiltration and STOCKPIPE for proxying information through Microsoft Exchange servers over email. BRONZE VAPOR uses a set of tactics that, although not individually unique, when viewed in aggregate create a relatively distinct playbook. Intrusions begin with credential based attacks against an existing remote access solution (Citrix, VPN etc.) or B2B network access. Cobalt Strike is deployed into the environment and further access is then conducted via Cobalt Strike Beacon and other features of the platform. Sharphound is deployed to map out the victim's Active Directory infrastructure and and collect critical information about the domain including important account names. Command and control infrastructure is hosted on subdomains of Azure and Appspot services to blend in with legitimate traffic. The threat actor also registers their own domains for command and control, often with a "sync" or "update" related theme. WinRAR is commonly used for compressing data prior to exfiltration. Filenames for these archives often involve a string of numbers and variations of the word "update". Data is exfiltrated using WATERCYCLE to cloud based platforms such as OneDrive and GoogleDrive.
Executive Summary
BRONZE VAPOR is a Chinese-origin threat group targeting sectors like semiconductors and aviation for espionage, using tools such as Cobalt Strike and WATERCYCLE to steal intellectual property and personal data. Their operations span East Asia and Europe, posing significant risks to organizations in these industries.
Goals & Targeting
BRONZE VAPOR targets sectors like semiconductors for intellectual property theft, aviation for personally identifiable information (PII), and telecommunications for metadata. Their strategic objectives involve espionage to gather sensitive information for potential national or economic advantage. They initially focused on East Asia, particularly Taiwan, due to its semiconductor industry, but expanded to Europe in 2019 and beyond.
Enhanced Description
BRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin. Operating since at least 2017, they conduct espionage against multiple industries including semiconductors, aviation, and telecommunications. Their goal appears to be information theft, focusing on intellectual property (semiconductors) and personally identifiable information such as traveler records (aviation). They compromise telecommunications companies to obtain PII and metadata like Call Data Records (CDR). BRONZE VAPOR's tactics include initial access via VPN services, spearphishing with 'Letter of Appointment' themed lures, deployment of Cobalt Strike, AceHash for credential harvesting, WATERCYCLE for data exfiltration, and STOCKPIPE for proxying information through Microsoft Exchange servers. Their command and control infrastructure uses subdomains of Azure and Appspot services, often registering domains with themes like 'sync' or 'update'. Data is exfiltrated using legitimate cloud platforms such as OneDrive and Google Drive.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BRONZE VAPOR's campaigns show a focus on semiconductors, airlines, and telecommunications. Their tactics involve compromising VPN services or B2B network access to gain initial entry. They use legitimate tools within the environment, such as WinRAR for data compression, and exfiltrate data through cloud platforms like OneDrive and Google Drive. Notable operations include attacks on a European semiconductor company since 2017 and airline sector targets in 2019.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in BRONZE VAPOR's Chinese origin and espionage activities. Data gaps include exact origins, full scope beyond known campaigns, detailed TTPs, and precise impact assessment.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics