“Sharp Panda,” a cyberespionage linked to China, has expanded its targets to now include government organizations in Africa and the Caribbean.

“This campaign of cyber espionage uses the Cobalt Strike Beacon as a useful payload, allowing backdoor functions such as C2 communication and command execution, while simultaneously minimizing the exposure of their custom tools,” said Check Point in a report published on The Hacker News. “This refined tactic shows a deeper understanding of their targets.”
See also: USA: Visa restrictions on people involved in spyware
The Israeli cybersecurity is monitoring the activity of the new threat, dubbed Sharp Dragon, describing the adversary as being cautious in targeting while simultaneously expanding its reconnaissance efforts.
The threat first emerged in June 2021, when it was detected targeting a Southeast Asian government by deploying a backdoor to Windows systems named VictoryDLL.
Subsequent attacks by Sharp Dragon targeted high-profile government agencies in Southeast Asia, with the aim of delivering the Soul backdoor. This framework is then used to obtain additional data from a server controlled by the hackers, thus facilitating intelligence gathering.
Evidence suggests that the Soul backdoor has been in development since October 2017, incorporating features from the Gh0st RAT – a malware often associated with various Chinese threat actors – as well as other publicly available tools.
A recent series of attacks, attributed to threat actors, targeted high‑level government officials of G20 countries in June 2023. This indicates the ongoing focus on government entities for information gathering.
Key to Sharp Panda's operations is the exploitation vulnerabilities (e.g. CVE-2023-0669) to infiltrate the infrastructure and use it as command and control (C2) servers in the future. Another notable aspect is the use of the Cobalt Strike legitimate adversary simulation framework in conjunction with custom backdoors.
Furthermore, the most recent series of attacks targeting governments in Africa and the Caribbean shows an expansion of their original objectives. The tactic involves using compromised high-profile emails in Southeast Asia to send phishing emails.
These messages contain malicious attachments that exploit the Royal Road Rich Text Format (RTF) tool to install a downloader named 5.t. This program is responsible for the detection and creation of Cobalt Strike, allowing hackers to collect information about the target's environment.
Read also: Germany: Arrest warrants issued against individuals for Chinese espionage
The use of Cobalt Strike as a backdoor not only reduces the exposure of custom tools, but also proposes a more «refined approach to target assessment», as noted by Check Point.
As a sign of the threat actor's continued refinement of its tactics, a series of attacks have recently been observed that use executable files disguised as documents to initiate infection. This method differs from the previous one, which relied on a Word using a remote template to download an RTF file with malicious content.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The strategic expansion of Sharp Dragon into Africa and the Caribbean is part of a broader effort by Chinese cybercriminals to strengthen their presence and influence in these regions.
The findings are published on the same day that Palo Alto Networks revealed details about the campaign codenamed “Operation Diplomatic Spectre,” which has been targeting diplomatic missions and governments in the Middle East, Africa, and Asia since late 2022. The attacks are attributed to a Chinese threat group called TGR-STA-0043 (formerly CL-STA-0043).
Sharp Dragon's decision to move its operations to Africa is part of China's broader strategy to expand its influence across the entire continent.
«These attacks clearly align with China's broader soft power and technological agenda strategy in the region, emphasizing critical sectors such as telecommunications, financial institutions and government agencies», according to SentinelOne security researcher Tom Hegel.
This development follows a report by Mandiant, which belongs to Google, that highlighted the use of proxy networks by China. These are referred to as Operational Relay Networks (ORBs) and are used to conceal their origin during espionage operations, thereby achieving greater success in acquiring and maintaining access to valuable networks.
"Creating networks of hacked devices allows administrators to easily expand the size of their network with minimal effort, creating a constantly evolving mesh that can be used to hide espionage activities," said Mandiant researcher Michael Raggi.

A network named ORB3 (also known as SPACEHOP) is reported to have been exploited by multiple threat actors with connections to China, including APT5 and APT15. Additionally, another network, FLORAHOX, which includes devices recruited by the FLOWERWATER router implant, has been used by APT31.
See more: 'eXotic Visit' spyware targets Android users in India and Pakistan
“The use of ORB networks to proxy traffic across a compromised network is not a new tactic, nor is it exclusive to China-linked cyberespionage actors,” Raggi said. “We are seeing China using these methods as part of a broader evolution toward more strategic, covert, and efficient operations.”
Source: thehackernews
