BrazenBamboo is a well-resourced Chinese state-affiliated threat actor targeting domestic entities with LIGHTSPY, DEEPDATA, and DEEPPOST malware.
Analyst brief
BrazenBamboo is a well-resourced, likely Chinese state-affiliated threat actor focusing on domestic targets. It operates the LIGHTSPY, DEEPDATA, and DEEPPOST malware families, with capabilities for zero-day exploitation, specifically targeting vulnerabilities like FortiClient. Defenders should focus on their multi-platform C2 architecture and data exfiltration supported by custom analyst software, as the group actively develops its malware payloads.
BrazenBamboo
unknown
BrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families. Their infrastructure includes capabilities for zero-day exploitation, specifically targeting vulnerabilities like FortiClient, and employs a command-and-control architecture that supports multi-platform operations. Volexity's analysis indicates that BrazenBamboo is a well-resourced entity with a focus on domestic targets, utilizing custom analyst software to manage data collected from their malware. The ongoing development of their malware families is evidenced by the timestamps associated with their latest payloads.