EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Scraper: Rising Tide: Chasing the Currents of Espionage in the South China Sea

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 55/100

MISP EudorIA ha pubblicato l'advisory "Scraper: Rising Tide: Chasing the Currents of Espionage in the South China Sea". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: Scraper: Rising Tide: Chasing the Currents of Espionage in the South China Sea. Report from - [URL rimossa] (1663734637) html Skip to main content BlogThreat Insight Rising Tide: Chasing the Currents of Espionage in the South China Sea # Rising Tide: Chasing the Currents of Espionage in the South China Sea Share with your network! August 30, 2022 Michael Raggi and Sveva Scenarelli at PwC Proofpoint’s Threat Research Team details a recent cyber espionage campaign targeting entities globally and conducted by a threat actor publicly which was attributed in 2021 by multiple governments and was the focus of a 2021 indictment by the US Department of Justice. The targets of this recent campaign spanned Australia, Malaysia, and Europe, as well as entities that operate in the South China Sea. Proofpoint’s research has been assisted by the PwC Threat Intelligence team to provide the information security community with a comprehensive view of the threat activity described. ### Introduction Proofpoint and PwC Threat Intelligence have jointly identified a cyber espionage campaign, active since April 2022 through June, delivering the ScanBox exploitation framework to targets who visit a malicious domain posing as an Australian news website. The joint efforts of Proofpoint and PwC researchers provide a moderate confidence assessment that recent campaigns targeting the federal government, energy, and manufacturing sectors globally may represent recent efforts by TA423 / R

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it · translation not needed
Publication
30/07/2026 02:47
Sharing
TLP:CLEAR
Indicators reported by the source
81
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
43Last sharing verification: 2026-09-25T18:02:28.629406+00:00
MISP event
7f79ab3b-6744-4857-85a0-ec2803a67372
MITRE ATT&CK
Template Injection - T1221
Classification
Medium
Open the original source