As cited
Copy frozen at (site build).
threat intel
Risky Bulletin: New Chinese cyber contractor identified
Intrusion Truth researchers identified Guangdong Chanming, a Chinese IT company operating as a cyber contractor for state-sponsored hacking groups. The company appears to have developed RedRelay (also called ORBWEAVER), a proxy botnet used by approximately a dozen Chinese advanced persistent threat (APT) groups including APT15, Red Vulture, Ke3chang, and others to obfuscate attack origins.
Why it matters: Organizations targeted by Chinese APT groups should understand the infrastructure ecosystem enabling these attacks; defenders tracking RedRelay infrastructure can now attribute it to a specific contractor and potentially identify related tools and operations.
- Source published
- First seen by Cybersecurity Tracker