A China-based cyber espionage group targeting Southeast Asia, known for using custom malware toolsets.
Analyst brief
Camaro Dragon is a China-based cyber espionage threat actor whose activities overlap with Mustang Panda and LuminousMoth. The group primarily targets Southeast Asian countries and their close peers, with incidents also observed in Europe, such as a healthcare institution. Key TTPs involve the use of custom malware toolsets, as reported by Avast and investigated by CPIRT in early 2023. Defenders should focus on monitoring suspicious files, unusual network connections, and C2 communications associated with this actor's known tooling.
Camaro Dragon
unknown
In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution involving a set of tools mentioned in the Avast report in late 2022. The incident was attributed to Camaro Dragon, a Chinese-based espionage threat actor whose activities overlap with activities tracked by different researchers as Mustang Panda and LuminousMoth, whose focus is primarily on Southeast Asian countries and their close peers.