DragonSpark targets East Asian entities with SparkRAT and China Chopper webshells.
Analyst brief
DragonSpark is a cyber threat actor primarily targeting organizations in East Asia. Believed to be Chinese-speaking, they use compromised infrastructure located in China and Taiwan. Their key TTPs include the deployment of the multi-platform SparkRAT remote access Trojan, evasion through Golang source code interpretation, and the use of the China Chopper webshell. Defenders should focus on detecting SparkRAT network traffic, anomalous Golang code interpretation activity, and the presence of China Chopper webshells.
DragonSpark
unknown
DragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia. They utilize the open-source tool SparkRAT, which is a multi-platform and frequently updated remote access Trojan. The threat actor is believed to be Chinese-speaking based on their use of Chinese language support and compromised infrastructure located in China and Taiwan. They employ various techniques to evade detection, including Golang source code interpretation and the use of the China Chopper webshell.