DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltration operations that traditionally targeted gov't agencies and think tanks in Asia and Europe. DEV-0147 is known to use tools like ShadowPad, a remote access trojan associated with other China-based actors, to maintain persistent access, and QuasarLoader, a webpack loader, to deploy additional malware. DEV-0147's attacks in South America included post-exploitation activity involving the abuse of on-premises identity infrastructure for recon and lateral movement, and the use of Cobalt Strike for command and control and data exfiltration.
Executive Summary
DEV-0147 is a China-based cyber espionage threat actor targeting diplomatic entities globally, particularly expanding into South America. They employ advanced tools like ShadowPad and Cobalt Strike for persistent access and data exfiltration, posing significant risks to government agencies and think tanks.
Goals & Targeting
DEV-0147 targets diplomatic entities to gather intelligence, expanding regionally to diversify their sources. Their motivation aligns with broader Chinese espionage goals, focusing on government agencies and think tanks to collect high-value data for strategic gain.
Enhanced Description
DEV-0147, identified as a Chinese-based cyber espionage group, has shifted its focus from Asian and European targets to South American diplomatic entities. Known for using ShadowPad and QuasarLoader for initial breaches, the actor implements Cobalt Strike for C2 and data exfiltration. Their operations involve post-exploitation activities leveraging on-premises identity infrastructure, indicating a focus on recon and lateral movement. This strategic expansion underscores DEV-0147's intent to gather sensitive information, likely for geopolitical advantage.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DEV-0147's campaigns show a strategic shift in targeting, leveraging advanced tools for prolonged access and lateral movement. They maintain persistence and execute targeted data theft from diplomatic networks, notably in South America.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in DEV-0147's APT nature and toolset, yet limited details on exact campaigns reduce certainty. More data on specific campaign tactics would enhance analysis.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics