BRONZE EDGEWOOD is a China-nexus threat actor known for exploiting Microsoft Exchange Servers.
Analyst brief
BRONZE EDGEWOOD, also tracked as Red Hariasa, is a threat actor assessed to operate on behalf of the Chinese government. It has targeted government and private enterprises across Southeast Asia, notably in Kyrgyzstan, Malaysia, and Vietnam, since at least 2018. Key TTPs include exploiting Microsoft Exchange Server vulnerabilities, deploying China Chopper webshell, using Nishang PowerShell scripts, and leveraging Cobalt Strike alongside malware families like Chinoxy, PCShare, and FunnyDream. Defenders should prioritize patching Exchange servers, monitor for anomalous PowerShell execution and C2 connections, and hunt for the listed tools in their environments.
BRONZE EDGEWOOD
Red Hariasa
unknown
In early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast Asia. The threat group deployed a China Chopper webshell and ran the Nishang Invoke-PowerShellTcp.ps1 script to connect back to C2 infrastructure. The threat group is publicly linked to malware families Chinoxy, PCShare and FunnyDream. CTU researchers have discovered that BRONZE EDGEWOOD also leverages Cobalt Strike in its intrusion activity. BRONZE EDGEWOOD has been active since at least 2018 and targets government and private enterprises across Southeast Asia. CTU researchers assess with moderate confidence that BRONZE EDGEWOOD operates on behalf the Chinese government and has a remit that covers political espionage.