Lilac Typhoon
Aliases: DEV-0234
- First seen
- 2022-06-01 00:00:00
- Origin
- CN
- Primary motivation
- financial-gain
- Sophistication
- expert
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:12:52
Targeted industries: technology-and-telecommunications government-and-public-sector financial-services
Targeted regions: country_code:us country_code:gb country_code:au
Context
Lilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which allows for remote code execution. This vulnerability has been used in cryptojacking campaigns and is included in commercial exploit frameworks. Lilac Typhoon has also been involved in deploying various payloads such as Cobalt Strike, web shells, botnets, coin miners, and ransomware.
Exploited vulnerabilities
- CVE-2022-26134 (vulnerability)
Reports & references
- securityboulevard.com — Analysis Of Cisa Releases Advisory On Top Cves Exploited Chinese State Sponsored Groups (report)
- riskybiznews.substack.com — Risky Biz News Google Shuts Down (report)
- twitter.com — 1535417776290111489 (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)