Moshen Dragon is a Chinese-aligned cyberespionage group targeting the telecommunications sector in Central Asia.
Analyst brief
Moshen Dragon is a Chinese-aligned cyberespionage threat actor operating primarily in Central Asia. They specifically target the telecommunications sector. Key TTPs include DLL search order hijacking to sideload ShadowPad and PlugX variants, the use of a passive backdoor named GUNTERS, an LSA notification package, and Impacket for lateral movement. Defenders should focus on anomalous DLL loading, network signatures of Impacket usage, and indicators linked to their backdoors, especially in telecommunications environments.
Moshen Dragon
unknown
Moshen Dragon is a Chinese-aligned cyberespionage threat actor operating in Central Asia. They have been observed deploying multiple malware triads and utilizing DLL search order hijacking to sideload ShadowPad and PlugX variants. The threat actor also employs various tools, including an LSA notification package and a passive backdoor known as GUNTERS. Their activities involve targeting the telecommunication sector and leveraging Impacket for lateral movement and data exfiltration.