Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DEV-0147

Description

DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltration operations that traditionally targeted gov't agencies and think tanks in Asia and Europe. DEV-0147 is known to use tools like ShadowPad, a remote access trojan associated with other China-based actors, to maintain persistent access, and QuasarLoader, a webpack loader, to deploy additional malware. DEV-0147's attacks in South America included post-exploitation activity involving the abuse of on-premises identity infrastructure for recon and lateral movement, and the use of Cobalt Strike for command and control and data exfiltration.

AI Analysis

· 1 week ago

Executive Summary

DEV-0147 is a China-based cyber espionage threat actor targeting diplomatic entities globally, particularly expanding into South America. They employ advanced tools like ShadowPad and Cobalt Strike for persistent access and data exfiltration, posing significant risks to government agencies and think tanks.

Goals & Targeting

DEV-0147 targets diplomatic entities to gather intelligence, expanding regionally to diversify their sources. Their motivation aligns with broader Chinese espionage goals, focusing on government agencies and think tanks to collect high-value data for strategic gain.

Enhanced Description

DEV-0147, identified as a Chinese-based cyber espionage group, has shifted its focus from Asian and European targets to South American diplomatic entities. Known for using ShadowPad and QuasarLoader for initial breaches, the actor implements Cobalt Strike for C2 and data exfiltration. Their operations involve post-exploitation activities leveraging on-premises identity infrastructure, indicating a focus on recon and lateral movement. This strategic expansion underscores DEV-0147's intent to gather sensitive information, likely for geopolitical advantage.

Key Capabilities

  • Advanced persistent threat tactics
  • Use of ShadowPad and QuasarLoader
  • Cobalt Strike deployment
  • Post-exploitation activities including identity infrastructure abuse

MITRE ATT&CK Tactics

Initial Access
Credential Dumping
Exfiltration

ATT&CK Techniques

T1070
T1003
T1270.001

Software / Tooling

ShadowPad
QuasarLoader
Cobalt Strike

Campaigns & Victims

DEV-0147's campaigns show a strategic shift in targeting, leveraging advanced tools for prolonged access and lateral movement. They maintain persistence and execute targeted data theft from diplomatic networks, notably in South America.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Remote Desktop Protocol (RDP) lateral movement
  • Cobalt Strike C2 communication

Recommended Actions

  • Monitor for RDP lateral movement signs
  • Implement multi-factor authentication
  • Segment sensitive network areas
  • Regular software patching

Suggested Tags

APT
espionage
diplomatic sector

Confidence Assessment

High confidence in DEV-0147's APT nature and toolset, yet limited details on exact campaigns reduce certainty. More data on specific campaign tactics would enhance analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Data Exfiltration
Government Targeting
espionage
diplomatic sector

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.