Operation Wocao is a likely Chinese state-aligned cyber espionage group targeting government entities.
Analyst brief
Operation Wocao is a Chinese-based hacking group likely supporting state interests for cyber espionage. They target government entities and other sectors of strategic interest. Their TTPs are assessed with medium confidence to align with APT20. Defenders should focus on detecting unauthorized remote access tools and anomalous authentication patterns.
Operation Wocao
unknown
Operation Wocao (我操, “Wǒ cāo”, used as “shit” or “damn”) is the name that Fox-IT uses to describe the hacking activities of a Chinese based hacking group.
This report details the profile of a publicly underreported threat actor that Fox-IT has dealt with over the past two years. Fox-IT assesses with high confidence that the actor is a Chinese group and that they are likely working to support the interests of the Chinese government and are tasked with obtaining information for espionage purposes. With medium confidence, Fox-IT assesses that the tools, techniques and procedures are those of the actor referred to as APT20 by industry partners. We have identified victims of this actor in more than 10 countries, in government entities, managed service providers and across a wide variety of industries, including Energy, Health Care and High-Tech.
Which country is Operation Wocao associated with and what is its primary objective?+
Operation Wocao is assessed with high confidence by Fox-IT to be a Chinese group, likely working to support the interests of the Chinese government for cyber espionage purposes.
What should defenders focus on to detect Operation Wocao's activity?+
Defenders should focus on detecting anomalous authentication patterns and the use of unauthorized remote access tools, such as web shells.