Carderbee

First seen
2022-09-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:05:50

Targeted industries: technology-and-telecommunications government-and-public-sector financial-services

Targeted regions: country_code:hk

Context

Symantec recently reported on activity attributed to a threat actor group dubbed Carderbee. In the campaign, the threat actors target entities in Hong Kong and other regions of Asia via a supply chain attack leveraging the legitimate Cobra DocGuard software. The activity began as early as September 2022.

Reports & references

  • blog.eclecticiq.com — Chinese State Sponsored Cyber Espionage Activity Targeting Semiconductor Industry In East Asia (report)
  • blog.polyswarm.io — Carderbee Targets Hong Kong In Supply Chain Attack (report)
  • Broadcom/Symantec — Carderbee Software Supply Chain Certificate Abuse (report)

External references