Skip to content

Commit 3b5dd65

Browse files
committed
auditd_detection_updates
1 parent 5c4abbc commit 3b5dd65

File tree

2 files changed

+22
-21
lines changed

2 files changed

+22
-21
lines changed
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
name: China-Nexus Threat Activity
2+
id: 43f8062d-4da0-4f48-8cad-6a20e108961b
3+
version: 2
4+
date: '2025-02-24'
5+
author: Teoderick Contreras, Splunk
6+
status: production
7+
description: Leverage searches that allow you to detect and investigate unusual activities that might relate to Nexus, Chinese state-nexus adversaries known for its stealth and strategic targeting of high-value sectors. Monitor for indicators such as spear-phishing campaigns, exploitation of zero-day vulnerabilities, and unauthorized lateral movement within your network. Investigate anomalous data exfiltration, encrypted communications, and behaviors aligning with their known tactics, techniques, and procedures (TTPs). Combining threat intelligence with real-time monitoring helps identify and respond to Nexus APT activity, minimizing potential damage and data loss.
8+
narrative: Chinese state-nexus threat group are known to target the telecommunications and technology sectors in multiple countries, including the US, to maintain sustained access as well as conduct espionage. Compromised entities in either sector represent potential supply chain vectors of concern to Splunk, although telecommunications entities are a more pervasive and acute concern in this regard. These actors are also known to broadly target unpatched routers, switches and other edge devices across various sectors. Given these threats, Splunk Threat Intelligence (TI) undertook a detailed investigation into China-nexus tactics and techniques that could be used in attempts to compromise Splunk. This report is the result of that investigation, detailing noteworthy behaviors and tools employed by China-nexus targeted intrusion actors.
9+
references:
10+
- https://news.sophos.com/en-us/2024/10/31/pacific-rim-neutralizing-china-based-threat/
11+
- https://www.wsj.com/tech/cybersecurity/typhoon-china-hackers-military-weapons-97d4ef95?st=oe1KKi&reflink=desktopwebshare _permalink
12+
- https://www.judiciary.senate.gov/imo/media/doc/2024-11-19_pm_-_testimony_-_meyers.pdf
13+
- https://go.crowdstrike.com/rs/281-OBQ-266/images/GlobalThreatReport2024.pdf
14+
- https://www.crowdstrike.com/adversaries/envoy-panda/
15+
tags:
16+
category:
17+
- Malware
18+
product:
19+
- Splunk Enterprise
20+
- Splunk Enterprise Security
21+
- Splunk Cloud
22+
usecase: Advanced Threat Detection

stories/nexus_apt_threat_activity.yml

Lines changed: 0 additions & 21 deletions
This file was deleted.

0 commit comments

Comments
 (0)