Camaro Dragon

Threat Actor updated a month ago (2024-09-07T01:17:48.192Z)
Download STIX
Preview STIX
Camaro Dragon, a Chinese state-sponsored threat actor also known as Stately Taurus, Mustang Panda, Bronze President, Red Delta, Luminous Moth, and Earth Preta, has been active since at least 2012. In 2023, Checkpoint Research discovered a custom firmware image linked to Camaro Dragon that contained several malicious components, including an implant dubbed "Horse Shell". This group was found exploiting TP-Link routers via a malicious firmware implant in attacks on European foreign affairs entities. Notably, the IP address to which Horse Shell's C&C resolves is listed in Avast's report on Mustang Panda's activities. Significant overlaps between Mustang Panda and Camaro Dragon suggest that this router implant has likely been deployed in other campaigns by the group. The analysis of these implants provides insight into the techniques and tactics utilized by the Camaro Dragon APT group, demonstrating how threat actors use malicious firmware implants in network devices for their attacks. For instance, USB drives were identified as a primary infection vector for three major threat groups in 2023, including Camaro Dragon, as noted by Maya Horowitz, vice president of research at Check Point, in her keynote presentation at CPX 2024 in Las Vegas. The reach of Camaro Dragon's activities extends beyond institutional targets, with one incident involving a UK hospital employee unknowingly infecting the hospital's entire corporate network after catching the Camaro Dragon malware from an infected colleague. Given the capabilities exhibited by China-aligned threat actors such as Evasive Panda and TheWizards, as well as recent research on router implants attributed to BlackTech and Camaro Dragon, it is speculated that the attackers are deploying a network implant in the networks of the victims, potentially targeting vulnerable network appliances like routers or gateways.
Description last updated: 2024-09-07T00:22:49.737Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Mustang Panda is a possible alias for Camaro Dragon. Mustang Panda, a known Chinese advanced persistent threat (APT) group, has been identified as the likely perpetrator behind a sophisticated, ongoing cyber-espionage campaign. The group, also known as Stately Taurus, Bronze President, RedDelta, Luminous Moth, Earth Preta, and Camaro Dragon, has a 12-
6
Stately Taurus is a possible alias for Camaro Dragon. Stately Taurus, also known as Mustang Panda, Bronze President, Camaro Dragon, Earth Preta, Luminous Moth, and Red Delta, is a sophisticated malware strain that has been linked to various cyberespionage activities. The malware, which was observed by Palo Alto Networks' Unit 42 and Trend Micro among o
4
LuminousMoth is a possible alias for Camaro Dragon. LuminousMoth is a threat actor group with potential affiliations to a Chinese-speaking entity, exhibiting similar targeting and Tactics, Techniques, and Procedures (TTPs) as the HoneyMyte group. These similarities include the use of DLL side-loading, Cobalt Strike loaders, and a component akin to Lu
3
Earth Preta is a possible alias for Camaro Dragon. Earth Preta, also known as Mustang Panda or Stately Taurus, is a high-profile threat actor group that has been actively executing cyberattacks with malicious intent. Their activities have been particularly prevalent in the Asia Pacific (APAC) region and Europe. The group employs a variety of tools a
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Apt
Malware
Implant
Chinese
Backdoor
State Sponso...
Espionage
Firmware
Tp
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Raspberry Robin Malware is associated with Camaro Dragon. Raspberry Robin is a sophisticated piece of malware that uses a variety of tactics to infiltrate and exploit computer systems. It employs the CPUID instruction to conduct several checks, enabling it to assess the system's characteristics and vulnerabilities. Furthermore, Raspberry Robin has been obsUnspecified
2
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The RedDelta Threat Actor is associated with Camaro Dragon. RedDelta, also known as Bronze President, is a threat actor that has been conducting cyber-espionage attacks since 2014. It is one of the likely Ministry of State Security (MSS)-linked groups which include APT10, APT17, APT27, APT40, APT41, TAG-22, and RedBravo among others. The organization's activUnspecified
4
The Aqua Blizzard Threat Actor is associated with Camaro Dragon. Aqua Blizzard, previously known as ACTINIUM, is a significant threat actor originating from Russia. Recently, Microsoft revamped its naming convention for threat groups, transitioning from all-cap names based on atomic elements to a two-name scheme inspired by storm terminology. Aqua Blizzard has beUnspecified
2
The Gamaredon Threat Actor is associated with Camaro Dragon. Gamaredon is a threat actor, commonly believed to be a Russian Advanced Persistent Threat (APT) group, known for its aggressive approach and persistence in executing actions with malicious intent. The group has been particularly active against Ukraine, deploying a USB worm named LitterDrifter as parUnspecified
2
Source Document References
Information about the Camaro Dragon Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
a month ago
DARKReading
a month ago
Unit42
a month ago
InfoSecurity-magazine
2 months ago
InfoSecurity-magazine
3 months ago
InfoSecurity-magazine
6 months ago
Unit42
6 months ago
CERT-EU
7 months ago
DARKReading
7 months ago
ESET
8 months ago
ESET
8 months ago
CERT-EU
10 months ago
Unit42
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Checkpoint
a year ago