Lilac Typhoon

Aliases: DEV-0234

First seen
2022-06-01 00:00:00
Origin
CN
Primary motivation
financial-gain
Sophistication
expert
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:12:52

Targeted industries: technology-and-telecommunications government-and-public-sector financial-services

Targeted regions: country_code:us country_code:gb country_code:au

Context

Lilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which allows for remote code execution. This vulnerability has been used in cryptojacking campaigns and is included in commercial exploit frameworks. Lilac Typhoon has also been involved in deploying various payloads such as Cobalt Strike, web shells, botnets, coin miners, and ransomware.

Exploited vulnerabilities

  • CVE-2022-26134 (vulnerability)

Reports & references

  • securityboulevard.com — Analysis Of Cisa Releases Advisory On Top Cves Exploited Chinese State Sponsored Groups (report)
  • riskybiznews.substack.com — Risky Biz News Google Shuts Down (report)
  • twitter.com — 1535417776290111489 (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references