REF2924

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:06:30

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:in country_code:id

Context

A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed Naplistener by the researchers — in attacks against victims operating in southern and southeast Asia.According to a blog post by Elastic senior security research engineer Remco Sprooten, in that region of the world, network-based detection and prevention technologies are the de facto method for securing many environments.

Reports & references

  • elastic.co — Introducing The Ref5961 Intrusion Set (report)
  • elastic.co — Ref2924 Howto Maintain Persistence As An Advanced Threat (report)

External references