BRONZE SPRING (UNC302) is a China-aligned threat group known for intellectual property theft.
Analyst brief
BRONZE SPRING (UNC302) is a China-aligned threat group focused on intellectual property theft from defense, engineering, pharmaceutical, and technology sectors across the US, Europe, and Asia-Pacific. They typically use scan-and-exploit for initial access, deploy the China Chopper webshell for persistence and remote execution, and exfiltrate data in RAR archives disguised with a '.jpg' extension. Defenders should prioritize patching internet-facing vulnerabilities, monitoring for webshell activity indicative of China Chopper, and inspecting outbound network traffic for large data transfers using anomalous file extensions.
BRONZE SPRING
UNC302
unknown
BRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intellectual property from defense, engineering, pharmaceutical and technology companies. The threat group typically uses scan-and-exploit for initial access, deploys the China Chopper webshell for remote execution and persistence, and creates RAR archives with a '.jpg' file extension for data exfiltration.
In July 2020 the U.S. Department of Justice indicted two Chinese hackers CTU researchers assess are members of the BRONZE SPRING threat group. The Department of Justice allege these hackers were responsible for compromising networks of hundreds of organisations and individuals in the U.S. and abroad since 2009, and that exfiltrated data would be passed to the Chinese Ministry of State Security or sold for financial gain.
origin (suspected)
🇨🇳China
target countries (as stated by the source)
United StatesAustraliaBelgiumGermany
target sectors
Information technologyMedicalCivil engineeringBusiness