Cybersecurity firm Sygnia has revealed that a major Asian telecommunications company suffered a prolonged breach by Chinese state-sponsored hackers who remained undetected in its systems for over four years. The threat actor, tracked as “Weaver Ant,” demonstrated sophisticated stealth and persistence throughout the operation.
## Attack Methodology
The hackers initially compromised the telecom provider by exploiting a public-facing application to deploy two web shells:
– An encrypted variant of China Chopper, a tool commonly used by Chinese hacking groups
– A previously undocumented tool called “INMemory” that executes entirely in memory, leaving minimal forensic evidence
These web shells served as gateways for delivering additional payloads, including a recursive HTTP tunnel tool that facilitated lateral movement across the network via SMB protocols.
## Post-Exploitation Activities
Once established in the network, Weaver Ant conducted several sophisticated evasion and reconnaissance techniques:
– Patched Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) to avoid detection
– Executed PowerShell commands without launching PowerShell.exe
– Performed extensive reconnaissance of the Active Directory environment to identify high-privilege accounts and critical servers
## Attribution to China
Sygnia attributes the attack to China-based threat actors based on several factors:
– Use of the China Chopper web shell
– Deployment of Zyxel routers as Operational Relay Boxes to mask their infrastructure
– Working hours consistent with Chinese time zones
– Implementation of an Outlook-based backdoor previously linked to Emissary Panda
## Taiwan Accusations
In a related development, China’s Ministry of State Security recently accused four Taiwanese individuals allegedly connected to Taiwan’s Information, Communications, and Electronic Force Command of conducting cyber attacks against mainland China. Taiwan has denied these allegations.
The Chinese government claims these actors used tools like AntSword web shell, IceScorpion, Metasploit, and Quasar RAT in their operations, while Chinese security firms QiAnXin and Antiy report observing spear-phishing campaigns attributed to a Taiwanese threat actor known as APT-Q-20.
