CardinalLizard is a China-linked cyber threat actor active since 2018, known for targeted spear-phishing and custom malware in the Asia region.
Analyst brief
CardinalLizard is a cyber threat actor linked to China, active since 2018, primarily targeting entities in the Asia region. Their key TTPs involve targeted spear-phishing campaigns and deploying custom malware with anti-detection features, alongside the potential use of shared infrastructure with other actors. Defenders should prioritize email security to detect and block spear-phishing attempts, and strengthen network monitoring for lateral movement and anomalous connections linked to suspicious infrastructure.
CardinalLizard
unknown
CardinalLizard, a cyber threat actor linked to China, has targeted entities in Asia since 2018. Their methods include spear-phishing, custom malware with anti-detection features, and potentially shared infrastructure with other actors.