Close Menu
  • Home
  • News
  • Tech Jungle
  • RAWRMag
  • BIZnest
  • Brands
  • About
    • BE PART OF THE LIONHEARTV FAMILY!
    • THE PRIDE
    • ADVERTISE AT LIONHEARTV
What's Hot

Megaworld Lifestyle Malls Earns 12 Recognitions at the 22nd Philippine Quill Awards

August 30, 2026

realme 16T 5G launches in the Philippines for as low ₱37/day via Home Credit

August 30, 2026

Charo Santos Has Entered Her Social Media Darling Era

August 30, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube TikTok
LionhearTVLionhearTV
  • Home
  • News
  • Tech Jungle
  • RAWRMag
  • BIZnest
  • Brands
  • About
    • BE PART OF THE LIONHEARTV FAMILY!
    • THE PRIDE
    • ADVERTISE AT LIONHEARTV
LionhearTVLionhearTV
Home»Press Release»Operation Crimson Palace, Chinese State-Sponsored Espionage, Expands in Southeast Asia, Sophos Report Finds
Press Release

Operation Crimson Palace, Chinese State-Sponsored Espionage, Expands in Southeast Asia, Sophos Report Finds

Lion's DenBy Lion's DenSeptember 17, 2024No Comments4 Mins Read
Share
Facebook Twitter Reddit Pinterest Email

Sophos, a global leader of innovative security solutions for defeating cyberattacks, recently released its report, “Crimson Palace: New Tools, Tactics, Targets,” which details the latest developments in a nearly two-year long Chinese cyberespionage campaign in Southeast Asia.

Sophos X-Ops first reported on what they named Operation Crimson Palace in June and detailed Sophos X-Ops’ discovery of three separate clusters of Chinese nation-state activity—Cluster Alpha, Cluster Bravo and Cluster Charlie—inside a high-profile government organization. After a brief hiatus in August 2023, Sophos X-Ops noted renewed Cluster Bravo and Cluster Charlie activity, both within the initial targeted organization and in numerous other organizations within the region.

While investigating this renewed activity, Sophos X-Ops uncovered a novel keylogger that the threat hunters named “Tattletale,” which can impersonate users who have signed into the system and gather information related to password policies, security settings, cached passwords, browser information, and storage data. Sophos X-Ops also notes in the report that, in contrast to the first wave of the operation, Cluster Charlie increasingly switched to using open-source tools rather than deploying the types of custom malware they developed in the initial wave of activity.

“We’ve been in an ongoing chess match with these adversaries. During the initial phases of the operation, Cluster Charlie was deploying various bespoke tools and malware,” said Paul Jaramillo, director, threat hunting and threat intelligence, Sophos. “However, we were able to ‘burn’ much of their previous infrastructure, blocking their Command and Control (C2) tools and forcing them to pivot. This is good; however, their switch to open-source tools demonstrates just how quickly these attacker groups can adapt and remain persistent. It also appears to be an emerging trend among Chinese nation-state groups. As the security community works to secure our most sensitive systems from these attackers, it’s important to share the insights into this pivot.”

Cluster Charlie, which shares tactics, techniques and procedures (TTPs) with the Chinese threat group Earth Longzhi, was originally active from March to August 2023 in a high-level government organization in Southeast Asia. While the cluster was dormant for several weeks, it re-emerged in September 2023 and was active again until at least May 2024. During this second stage of the campaign, Cluster Charlie focused on penetrating deeper into the network, evading endpoint detection and response (EDR) tools and gathering further intelligence. In addition to switching to open-source tools, Cluster Charlie also began using tactics initially deployed by Cluster Alpha and Cluster Bravo, suggesting that the same overarching organization is directing all three activity clusters. Sophos X-Ops has tracked ongoing Cluster Charlie activity across multiple other organizations in Southeast Asia.

Cluster Bravo, which shares TTPs with the Chinese threat group Unfading Sea Haze, was originally only active in the targeted network for a three-week span in March 2023. However, the cluster reappeared in January 2024, only this time it was targeting at least 11 other organizations and agencies in the same region.

“Not only are we seeing all three of the ‘Crimson Palace’ clusters refine and coordinate their tactics, but they’re also expanding their operations, attempting to infiltrate other targets in Southeast Asia. Given how frequently Chinese nation-state groups share infrastructure and tools, and the fact that Cluster Bravo and Cluster Charlie are moving beyond the original target, we will likely continue to see this campaign evolve—and in potentially new locations. We will be monitoring it closely,” said Jaramillo.

To learn more, read “Crimson Palace: New Tools, Tactics, Targets” on Sophos.com. For details about Sophos’ threat hunting and other services for disrupting cyberattacks, go to Sophos Managed Detection and Response (MDR).
For an in-depth look at the threat hunting behind this nearly two-year long cyber espionage campaign, register for the upcoming webinar “Intrigue of the Hunt: Operation Crimson Palace: Unveiling a Multi-Headed State-Sponsored Campaign” on Sept. 24 at 2 PM ET: https://events.sophos.com/operation-crimson-palace/.

Comments

Cluster Alpha Cluster Bravo Cluster Charlie Crimson Palace: New Tools Operation Crimson Palace Sophos Sophos X-Ops
Share. Facebook Twitter Pinterest LinkedIn Reddit Email
Previous ArticleBLIND ITEM: Department head at major TV network forced to step down early?
Next Article Cheska and Kendra Kramer advocates for Cervical Cancer Awareness and Prevention
Lion's Den
  • Website
  • Facebook
  • X (Twitter)
  • Instagram

LionhearTV has always believed in what the everyday reader can contribute, and has always been open to receiving input, help, or leads on stories. Readers are always encouraged to drop us their thoughts either by either by leaving a comment on a post, or contact us directly – email us at [email protected].

Related Posts

Megaworld Lifestyle Malls Earns 12 Recognitions at the 22nd Philippine Quill Awards

August 30, 2026

realme 16T 5G launches in the Philippines for as low ₱37/day via Home Credit

August 30, 2026

The OPPO Reno16 Series 5G Is Ready for Your First Barkada Moments on Campus

August 30, 2026

Head & Shoulders Unveils Complete Scalp Care Range with Skincare Ingredients at the Scalp Expert Lounge

August 30, 2026
Add A Comment

Comments are closed.

Find us on Facebook
Blogmeter.Top



Trending

WRIVE: The P-Pop Powerhouse That Has Arrived

August 3, 2026

SILOG Awards 2026 returns to honor Filipino online creators and digital mavericks

May 13, 2026

Lion With A Heart Year 9, from acts of giving to sustainable impact

April 28, 2026

LionhearTV continues to grow: Strengthening BIZNest, Tech Jungle, and RAWRTrip for 2026

February 14, 2026

15 Adored PH Celebrity Loveteams That Eventually Parted Ways

February 2, 2026
Showbiz News

‘Pepito Manaloto’, ‘KMJS’ maintain back-to-back weekend ratings board leadership

August 30, 2026

Mikee Quintos reveals she confronted Sassa Gurl over content mocking her thesis controversy

August 30, 2026

Filipino-made animated musical ‘Plump Blossom’ heads to cinemas amid debate over AI use

August 30, 2026

Makagago sparks buzz after claiming Josh Mojica, Yumi Garcia were together in Thailand

August 30, 2026

Vice Ganda acknowledges TV industry’s struggles, says collaboration is key to survival

August 29, 2026
Most Viewed

Megaworld Lifestyle Malls Earns 12 Recognitions at the 22nd Philippine Quill Awards

August 30, 2026

realme 16T 5G launches in the Philippines for as low ₱37/day via Home Credit

August 30, 2026

Charo Santos Has Entered Her Social Media Darling Era

August 30, 2026

‘Call Me Mother’ hits no. 1 on Netflix Philippines’ Top Movies

August 30, 2026

The OPPO Reno16 Series 5G Is Ready for Your First Barkada Moments on Campus

August 30, 2026
eMVP Digital is an online empire that useful pieces of information and a resource for a daily dose of entertainment in all forms. It produces LionhearTV.net, Dailypedia.net, RAWR Awards, RAWRMag, DailyPIPOL, and Broken Lion. These platforms have a highly-engaged audience per month, which varies from ages and sexes.



Blogmeter.Top
© 2026 LionhearTV.net.
  • Home
  • News
  • Tech Jungle
  • RAWRMag
  • BIZnest
  • Brands
  • About
    • BE PART OF THE LIONHEARTV FAMILY!
    • THE PRIDE
    • ADVERTISE AT LIONHEARTV

Type above and press Enter to search. Press Esc to cancel.