Lancefly
- First seen
- 2018-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:05:26
Targeted industries: government-and-public-sector technology-and-telecommunications transportation-and-logistics
Targeted regions: country_code:in country_code:sg country_code:my
Context
Lancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, and employ various tactics to gain access, including phishing emails, SSH credential brute-forcing, and exploiting server vulnerabilities. Additionally, Lancefly has been observed using a newer version of the ZXShell rootkit and tools like PlugX and ShadowPad RAT, which are typically associated with Chinese-speaking APT groups.
Reports & references
- Broadcom/Symantec — Lancefly Merdoor Zxshell Custom Backdoor (report)