CN

BrazenBambooBrazenBamboo

Also known as: BrazenBamboo

Origin
CN
Known aliases
1

Profile

BrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families. Their infrastructure includes capabilities for zero-day exploitation, specifically targeting vulnerabilities like FortiClient, and employs a command-and-control architecture that supports multi-platform operations. Volexity's analysis indicates that BrazenBamboo is a well-resourced entity with a focus on domestic targets, utilizing custom analyst software to manage data collected from their malware. The ongoing development of their malware families is evidenced by the timestamps associated with their latest payloads.

Aliases· 1

BrazenBamboo

References

  1. https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Flax Typhoon
Actor
Blackwood
Actor
DragonSpark
Actor
BAMBOO SPIDER
Actor
BRONZE STARLIGHT
Actor
CardinalLizard
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.