Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Lancefly

Description

Lancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, and employ various tactics to gain access, including phishing emails, SSH credential brute-forcing, and exploiting server vulnerabilities. Additionally, Lancefly has been observed using a newer version of the ZXShell rootkit and tools like PlugX and ShadowPad RAT, which are typically associated with Chinese-speaking APT groups.

AI Analysis

· 1 week ago

Executive Summary

Lancefly is an advanced persistent threat (APT) group targeting government, aviation, and telecom organizations in South and Southeast Asia. They employ a variety of attack techniques including phishing, SSH credential brute-forcing, server vulnerability exploitation, and deployment of custom malware such as Merdoor backdoor, ZXShell rootkit, PlugX, and ShadowPad RAT.

Goals & Targeting

Lancefly's strategic objectives likely revolve around collecting sensitive information from targeted sectors such as government for diplomatic or military intelligence. Their focus on aviation and telecom may aim at gathering technological insights or operational data. The choice of specific regions indicates a potential regional focus or resource availability.

Enhanced Description

Lancefly is suspected to be an APT group with heightened activity since 2018. They primarily target government, aviation, telecom sectors in South and Southeast Asia, possibly for espionage or strategic information theft. Their arsenal includes Merdoor backdoor, ZXShell rootkit, PlugX, ShadowPad RAT. They use phishing emails, SSH brute-forcing, and server exploitation to infiltrate networks. The sophistication of their tools, like evolving ZXShell rootkit, suggests a level of expertise akin to other notable Chinese-speaking APTs.

Key Capabilities

  • Phishing emails
  • SSH credential brute-forcing
  • Exploiting server vulnerabilities
  • Custom malware (Merdoor, ZXShell rootkit)
  • PlugX and ShadowPad RAT

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion

ATT&CK Techniques

T1059.003
T1214
T1070

Software / Tooling

Merdoor
ZXShell
PlugX
ShadowPad RAT

Campaigns & Victims

Lancefly's campaigns since 2018 demonstrate persistence and adaptability, evolving their tools in response to defenses. Their targeting of specific sectors suggests a deliberate focus on information gathering rather than immediate disruption.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • SSH brute-force attempts at凌晨 hours
  • Deployment of custom backdoors
  • C2 communications via IRC or HTTP

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts
  • Monitor SSH traffic for unauthorized access patterns
  • Patch server vulnerabilities promptly and regularly
  • Deploy EDR solutions to detect RAT activities
  • Conduct regular network monitoring using SIEM for异常流量识别

Suggested Tags

APT
Espionage
South Asia
Southeast Asia
Government
Telecom

Confidence Assessment

The available data on Lancefly provides moderate confidence in understanding their capabilities and targeting patterns. However, gaps exist in precisely mapping their long-term objectives, campaign structures, and specific infrastructure details, hindering more precise threat intelligence.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Government Targeting
Espionage
South Asia
Southeast Asia
Government
Telecom

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.