CeranaKeeper is a China-aligned APT group targeting governmental institutions across Asia.
Analyst brief
CeranaKeeper is a China-aligned APT group active since at least early 2022. It primarily targets governmental institutions in Asian countries. The group uses custom backdoors like TONESHELL and OneDoor, leverages cloud services such as Dropbox and OneDrive for data exfiltration, and employs TTPs including side-loading and brute-force attacks. Defenders should focus on monitoring unusual cloud service traffic, BAT script execution, and the deployment of novel backdoors.
CeranaKeeper
unknown
CeranaKeeper is a China-aligned APT that has been active since at least early 2022, primarily targeting governmental institutions in Asian countries. The group employs custom backdoors like TONESHELL and OneDoor, leveraging cloud services such as Dropbox and OneDrive for data exfiltration. CeranaKeeper utilizes techniques like side-loading, brute-force attacks, and the deployment of BAT scripts to extend its reach within compromised networks. Their operations are characterized by a relentless pursuit of sensitive data, adapting their toolset and methods to evade detection.