REF2924
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:06:30
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:in country_code:id
Context
A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed Naplistener by the researchers — in attacks against victims operating in southern and southeast Asia.According to a blog post by Elastic senior security research engineer Remco Sprooten, in that region of the world, network-based detection and prevention technologies are the de facto method for securing many environments.
Reports & references
- elastic.co — Introducing The Ref5961 Intrusion Set (report)
- elastic.co — Ref2924 Howto Maintain Persistence As An Advanced Threat (report)