BRONZE EDGEWOOD
Aliases: Red Hariasa
- First seen
- 2018-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:48:04
Targeted industries: government-and-public-sector technology-and-telecommunications professional-services
Targeted regions: country_code:vn country_code:th country_code:my country_code:id
Context
In early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast Asia. The threat group deployed a China Chopper webshell and ran the Nishang Invoke-PowerShellTcp.ps1 script to connect back to C2 infrastructure. The threat group is publicly linked to malware families Chinoxy, PCShare and FunnyDream. CTU researchers have discovered that BRONZE EDGEWOOD also leverages Cobalt Strike in its intrusion activity. BRONZE EDGEWOOD has been active since at least 2018 and targets government and private enterprises across Southeast Asia. CTU researchers assess with moderate confidence that BRONZE EDGEWOOD operates on behalf the Chinese government and has a remit that covers political espionage.
Reports & references
- pwc.com — Yir Cyber Threats Report Download (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)