Unfading Sea Haze

First seen
2018-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-21 08:35:25
Profile updated
2026-07-07 12:15:30

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:cn country_code:ph country_code:vn country_code:my

Context

Unfading Sea Haze is a threat actor focused on espionage, targeting government and military organizations in the South China Sea region since 2018. They employ spear-phishing emails with malicious attachments to gain initial access, followed by the deployment of custom malware such as Gh0st RAT variants and SharpJSHandler. The group utilizes scheduled tasks and manipulates local administrator accounts for persistence, while also incorporating Remote Monitoring and Management tools into their attacks. Unfading Sea Haze demonstrates a sophisticated and patient approach, remaining undetected for years and showing adaptability through evolving exfiltration tactics and malware arsenal.

Reports & references

  • securityweek.com — Newly Detected Chinese Group Targeting Military Government Entities (report)
  • bleepingcomputer.com — Unfading Sea Haze Hackers Hide On Military And Govt Networks For 6 Years (report)

External references