china
BRONZE WOODLAND
Objectives
Aliases
Tools
SUMMARY
BRONZE WOODLAND, active since June 2014, has been observed leveraging phishing lures with Mandarin Chinese language artifacts and deploying the PlugX RAT. It has historically targeted entities in Russia and members of the Commonwealth of Independent States (CIS), specifically Belarus, Kazakhstan, Kyrgyzstan, Tajikistan, Ukraine and Uzbekistan. CTU researchers assess with moderate confidence that BRONZE WOODLAND operates on behalf of China.
Contact Us
Contact us directly whether your organization needs immediate assistance or you want to discuss your incident readiness, response, and testing needs.