In a shocking revelation, cybersecurity firm Sygnia has reported that a major Asian telecommunications company was compromised by a group of Chinese state-sponsored hackers. This long-term breach, carried out by a group identified as Weaver Ant, allowed the attackers to quietly operate within the network for over forty eight months, collecting sensitive information without being detected.

Although the name of the affected telecom provider has not been disclosed, the implications are significant, highlighting the evolving strategies and persistence of modern cyber espionage operations.


Weaver Ant — A Stealthy and Persistent Threat Actor

Sygnia describes Weaver Ant as a stealth-focused, highly persistent group with clear goals tied to intelligence gathering and cyber espionage. The group exploited a misconfiguration in a public-facing application, which granted them an initial foothold in the target’s infrastructure.

Once inside, the attackers deployed two separate web shells to maintain access:

  • A customized, encrypted version of China Chopper, a widely used web shell by Chinese actors
  • A new, undocumented in-memory tool known as INMemory

INMemory works by decoding Base64-encoded strings and executing them directly in memory. This approach leaves no trace on disk, making forensic analysis extremely difficult.


Tools and Tactics Used in the Attack

The attackers used a wide range of tools and techniques to expand their reach and avoid detection. These include:

  • Recursive HTTP tunneling for lateral movement via SMB
  • Encrypted web shell traffic as a control channel for post-exploitation actions
  • Disabling detection systems by patching Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI)
  • Executing PowerShell commands via System Management Automation without launching PowerShell.exe
  • Targeted reconnaissance of Active Directory environments to locate privileged accounts and high-value systems

This combination of tactics illustrates a sophisticated understanding of enterprise networks and a methodical approach to persistent access and surveillance.


Indicators of a China Nexus

Several clues strongly point to the group being aligned with Chinese state interests. These include:

  • Use of China Chopper
  • Deployment of a backdoor using Microsoft Outlook, previously linked to Emissary Panda
  • Use of a relay network of Zyxel routers, called the Operational Relay Box (ORB), to hide traffic
  • Working hours that align with China Standard Time
  • Campaign goals focused on long-term access and intelligence gathering

Sygnia emphasized that Weaver Ant’s tactics resemble those of other China-linked groups, with shared infrastructure and overlapping toolsets. In some cases, this may involve contracted cyber operatives working across multiple campaigns.


Related Espionage Accusations Between China and Taiwan

This report coincides with recent accusations from China’s Ministry of State Security (MSS), which named four Taiwanese individuals allegedly involved in cyber attacks against mainland entities.

According to the MSS, these individuals belong to Taiwan’s Information, Communications, and Electronic Force Command (ICEFCOM). The group is accused of executing cyber operations such as:

  • Spear phishing campaigns
  • Disinformation and propaganda through fake social media accounts
  • Cyber sabotage and espionage

Chinese cybersecurity firms QiAnXin and Antiy added that these campaigns often used:

  • Open-source tools like AntSword, IceScorpion, Metasploit, and Quasar RAT
  • Command-and-control (C2) frameworks like Cobalt Strike and Sliver
  • Vulnerabilities in outdated routers, cameras, and firewalls for initial access

However, Taiwanese authorities have denied all accusations, escalating digital tensions in the region.


A Growing Pattern in Asia Pacific Cybersecurity

The breach of the Asian telecom provider, combined with the political accusations involving Taiwan, underscores a growing trend: Asia Pacific is becoming a central battleground for nation-state cyber conflict.

Telecommunications infrastructure, in particular, has become a high-priority target. With access to these systems, attackers can monitor communications, intercept data, and track users across the region.

“Weaver Ant adapted their techniques as the network evolved, always finding new ways to maintain access,” Sygnia noted in its report. “This reflects the hallmark behavior of a highly funded, state-linked threat group with specific intelligence objectives.”


Recommendations for Telecom and Enterprise Security Teams

In light of these events, organizations — especially telecom and critical infrastructure providers — must reevaluate their security posture. Key steps include:

  • Performing regular configuration audits to detect misconfigured public-facing applications
  • Monitoring for web shells and in-memory payloads using behavioral detection tools
  • Segmenting networks and limiting lateral movement through strict access controls
  • Deploying endpoint detection and response solutions capable of catching stealthy activity
  • Conducting threat hunting to identify signs of long-term compromise

These measures can help organizations respond to the new era of cyber espionage, where attacks are no longer just short-lived incidents, but multi-year campaigns aimed at systemic surveillance and influence.

FAQs

Who is Weaver Ant?
Weaver Ant is a Chinese state-sponsored threat actor known for cyber espionage. They recently infiltrated an Asian telecom provider and remained undetected for over four years.

How did they gain access?
The attackers exploited a misconfigured public-facing application and installed encrypted web shells for persistent access.

What is INMemory?
INMemory is a newly discovered web shell that executes code entirely in memory, leaving minimal forensic evidence.

What data did the attackers target?
They targeted sensitive systems, including Active Directory and email servers, seeking to identify privileged accounts and maintain long-term surveillance.

Are these attacks linked to China?
Yes, based on tool usage, working hours, and targeting patterns, Sygnia attributes the campaign to a China-nexus cyber espionage group.

What tools did they use?
Besides INMemory and China Chopper, the attackers used PowerShell automation, HTTP tunneling, AMSI evasion, and an Outlook-based backdoor.

Author

Share.

127 Comments

  1. Okay, so tried Bongvip. Pretty straightforward. Good selection of games especially Asian focused ones. Nothing groundbreaking, but a solid option if you’re looking for something new. Check’em out. bongvip

  2. q36game Official Site: Easy Login, Register, App Download & Best Slot Online in the Philippines Join the q36game official site, the #1 slot online in the Philippines. Fast q36game login, easy q36game register, and q36game app download. Start winning today! visit: q36game

  3. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  4. I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.

  5. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  6. I could feel real warmth and real thought behind each decision here and that pairing kept me reading right to the end. Your examples were so clear and familiar that I kept noticing my own everyday life reflected inside every single one. I intend to share this with a few people who truly need to read these exact words at this exact point in their lives.

  7. You have a rare knack for making a reader feel welcomed rather than counted as one more fleeting scroll in a feed. The way you carried me smoothly from one idea to the next made the whole post feel like one continuous flowing thought. So please do not slow down now because you are barely warming up and your very best work is still waiting up the road.

  8. This is exactly the sort of quiet encouragement I did not realize I needed until your words placed it before me today. So many sentences here read like quiet truths I had waited a long while to finally hear spoken with real conviction. Whatever fuels writing this genuine please guard it fiercely because it is producing work that truly helps real people.

  9. I have filed away plenty of posts across the years yet only a rare handful earned it as quickly and fully as this one did. The attention you paid to even the tiniest details shows me how much respect you carry for the craft of writing itself. Here is to so many more pieces just like this one and to the beautiful momentum you are so plainly building already.

  10. I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.

  11. Mầm Non Đồng Nai Nhắc đến cái tên này mình lại nhớ về những kỷ niệm hồn nhiên của thời thơ ấu dưới mái trường mầm non thân thương. Nhìn các bé bây giờ được học tập và vui chơi trong môi trường đầy đủ tiện nghi như thế này, mình cảm thấy thật sự ngưỡng mộ và thầm mong các con sẽ luôn có những năm tháng đầu đời thật rực rỡ. Hy vọng rằng nhà trường sẽ mãi giữ vững tâm huyết để trở thành bệ phóng vững chắc, nuôi dưỡng tâm hồn và trí tuệ cho các mầm non tương lai của tỉnh nhà. relay trace

  12. What makes this news particularly concerning is the apparent collusion between Chinese state interests and other known espionage groups, hinting at a broader pattern of coordinated cyber attacks targeting both Taiwan and its allies. This situation highlights the need for stronger international cooperation in cybersecurity and stricter regulations to prevent such breaches from happening again. Chọn Trường Mầm Non Sài Gòn. Insights Box

  13. Wow, what a shocking discovery! As an AI assistant, I am here to inform you that Chinese hackers have been quietly breaching a major Asian telecom provider for over four years, undetected by anyone. This revelation highlights just how pervasive cyber espionage has become in today’s world. Sổ tay mần non, it is truly concerning and brings into stark focus the need for increased vigilance and robust cybersecurity measures worldwide. routers for

  14. While it’s tempting to dismiss this as a distant threat, the truth is much closer than we think. It’s time for governments and businesses alike to invest in robust cybersecurity measures and collaboration across sectors to prevent such breaches from becoming an even more significant issue. I hope Sygnia’s report serves as a wake-up call and prompts stronger responses and stricter regulations against state-sponsored cyber threats. Mầm non hà nội. Time the

  15. Trường học mầm non phía nam đã mở khóa cánh cửa mới cho những đứa trẻ không may mắn có cơ hội tiếp cận với dịch vụ giáo dục chất lượng và phù hợp. Những chương trình này không chỉ giúp các em phát triển kỹ năng và kiến thức, mà còn tạo điều kiện để họ tìm ra con đường tốt đẹp nhất cho tương lai. Hot Tumblr

  16. Giáo dục mầm non miền bắc Thực sự thì môi trường học tập ở ngoài này có những nét đặc thù rất riêng, từ cách các cô giáo rèn nền nếp cho trẻ cho đến sự quan tâm sát sao của gia đình. Mỗi lần nhìn thấy các bé tung tăng đến trường trong những ngày thời tiết thay đổi, mình lại thấy trân trọng hơn sự vất vả và tâm huyết mà đội ngũ giáo viên đã dành cho thế hệ tương lai. Hy vọng rằng những phương pháp giáo dục hiện đại sẽ ngày càng được áp dụng rộng rãi hơn để các con có được một tuổi thơ trọn vẹn và phát triển toàn diện cả về thể chất lẫn tâm hồn. Chinese Stealthy

  17. Mầm chòi Lá: Wow, this is quite alarming news! It’s concerning how these Chinese hackers managed to breach the security system of an Asian telecom without being detected for so long. I’m curious about their tactics and tools used in such a sophisticated cyberattack. The fact that they could operate undetected for nearly half a decade is truly shocking. contracted Campaign

  18. Việt Nam Preschool Resourcces Cảm ơn bạn đã chia sẻ nguồn tài liệu hữu ích này, mình tìm kiếm những nội dung chất lượng như thế này từ lâu rồi để phục vụ cho việc giảng dạy các bé tại lớp. Những học liệu này thực sự rất trực quan và sinh động, chắc chắn sẽ giúp các con hứng thú hơn nhiều trong mỗi giờ học. Hy vọng bạn sẽ tiếp tục cập nhật thêm nhiều ý tưởng sáng tạo và bổ ích như vậy để cộng đồng giáo viên mầm non chúng mình có thêm cơ hội học hỏi lẫn nhau. Tumblr accounts

  19. Hello, you used to write great, but the last several posts have been kinda boring… I miss your super writings. Past few posts are just a little bit out of track! come on!

  20. tiểu học hội nhập quốc tế bamboo quận 12 Mình đang cân nhắc cho bé nhà mình theo học ở đây nên cũng tìm hiểu khá kỹ về chương trình giảng dạy và cơ sở vật chất. Thấy môi trường ở Bamboo có vẻ rất năng động, chú trọng vào cả ngoại ngữ lẫn kỹ năng mềm nên mình cũng an tâm hơn phần nào. Không biết có phụ huynh nào đang có con học tại trường có thể chia sẻ thêm cho mình một chút kinh nghiệm thực tế về cách thầy cô quan tâm đến các bé không ạ. Mình rất muốn nghe thêm những đánh giá khách quan để có quyết định chính xác nhất cho tương lai của con. point China

  21. Honestly this is exactly what the online gaming community in Vietnam has been waiting for. The login process is seamless and I never get locked out during tournaments. The daily rewards keep coming and the game selection covers all my favorites. It feels like a truly local platform that understands what players actually need. Visit vn13wi to see for yourself.

  22. My go to spot for quick entertainment during weekends. The platform loads fast and the game variety keeps me hooked without any boredom. I really appreciate how smooth the deposit and cash out process is compared to other sites I tried. Will keep coming back for sure. 786btapp

  23. Logging in never felt this seamless before. The platform runs smoothly on my phone and I love the quick access to all my favorite games. Customer support is also super helpful whenever I need a hand. phl163login

  24. Heya! I just wanted to ask if you ever have any problems with hackers? My last blog (wordpress) was hacked and I ended up losing months of hard work due to no backup. Do you have any methods to protect against hackers?

Leave A Reply

© 2026 ThemeSphere. Designed by ThemeSphere.
Exit mobile version