Carderbee is an Asia-focused cybercriminal group known for conducting supply chain attacks via legitimate software.
Analyst brief
Carderbee is a threat actor likely motivated by cybercrime, active since at least September 2022. The group primarily targets entities in Hong Kong and other parts of Asia using a supply chain attack that leverages the legitimate Cobra DocGuard software. A key TTP in this campaign is the exploitation of software supply chain dependencies to deliver malicious payloads. Defenders should focus on verifying the integrity of software updates, enhancing supply chain risk monitoring, and tightening security controls specifically around partner software used within the Asia-Pacific region.
Carderbee
unknown
Symantec recently reported on activity attributed to a threat actor group dubbed Carderbee. In the campaign, the threat actors target entities in Hong Kong and other regions of Asia via a supply chain attack leveraging the legitimate Cobra DocGuard software. The activity began as early as September 2022.