Carderbee
- First seen
- 2022-09-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:05:50
Targeted industries: technology-and-telecommunications government-and-public-sector financial-services
Targeted regions: country_code:hk
Context
Symantec recently reported on activity attributed to a threat actor group dubbed Carderbee. In the campaign, the threat actors target entities in Hong Kong and other regions of Asia via a supply chain attack leveraging the legitimate Cobra DocGuard software. The activity began as early as September 2022.
Reports & references
- blog.eclecticiq.com — Chinese State Sponsored Cyber Espionage Activity Targeting Semiconductor Industry In East Asia (report)
- blog.polyswarm.io — Carderbee Targets Hong Kong In Supply Chain Attack (report)
- Broadcom/Symantec — Carderbee Software Supply Chain Certificate Abuse (report)