Lancefly

First seen
2018-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:05:26

Targeted industries: government-and-public-sector technology-and-telecommunications transportation-and-logistics

Targeted regions: country_code:in country_code:sg country_code:my

Context

Lancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, and employ various tactics to gain access, including phishing emails, SSH credential brute-forcing, and exploiting server vulnerabilities. Additionally, Lancefly has been observed using a newer version of the ZXShell rootkit and tools like PlugX and ShadowPad RAT, which are typically associated with Chinese-speaking APT groups.

Reports & references

  • Broadcom/Symantec — Lancefly Merdoor Zxshell Custom Backdoor (report)

External references