REF5961
REF5961 is an intrusion set identified by Elastic Security Labs and assessed with confidence as China-nexus, state-sponsored, and espionage-motivated. Elastic reported REF5961 targeting the Foreign Affairs Ministry of an ASEAN member state and disclosed three malware families associated with the intrusion set: EAGERBEE, RUDEBIRD, and DOWNTOWN (also referred to as PhantomNet). BLOODALCHEMY, an x86 backdoor discovered as shellcode injected into a signed benign process, is also described as part of the REF5961 intrusion set. Elastic linked REF5961 to previously reported REF2924 activity through co-resident malware, overlapping infrastructure, and execution-flow similarities, and noted overlaps with reporting on LuckyMouse/APT27/Emissary Panda and TA428/Colourful Panda/BRONZE DUDLEY. Sophos later reported overlaps between its Cluster Alpha activity in the Crimson Palace campaign and public reporting on REF5961, including use of EAGERBEE, RUDEBIRD, and DOWNTOWN/PhantomNet. Sophos assessed Crimson Palace with high confidence as Chinese state-sponsored and noted overlaps with REF5961, but did not attribute all activity to a single known actor. Observed tradecraft includes DLL sideloading, service-based persistence, lateral movement, reconnaissance, and use of multiple backdoors for persistent command and control. RUDEBIRD was observed launched from a path resembling a Sysinternals utility, with a parent process of w3wp.exe consistent with exploitation of an unpatched Microsoft Exchange vulnerability, and used PsExec for SYSTEM execution and lateral movement. EAGERBEE supports forward and reverse C2, proxy awareness, optional SSL, and in-memory execution of downloaded PE payloads. DOWNTOWN is a modular plugin-based implant aligned with SManager/PhantomNet. BLOODALCHEMY supports persistence via service, registry Run key, scheduled task, or COM interfaces; process injection; and communications over HTTP, named pipes, or sockets. Elastic assessed with high confidence that EAGERBEE and RUDEBIRD were operated by the same tasking authority or organizational umbrella based on shared infrastructure patterns, hosted-by-bay[.]net subdomains, coordinated service enablement windows, and TLS artifacts. The reporting describes REF5961 as a developing and maturing intrusion set targeting ASEAN members.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Observables
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-nexus espionage actor referenced because Cluster Alpha overlaps in malware and C2 infrastructure, including use of EAGERBEE, RUDEBIRD, and PhantomNet/DOWNTOWN against a Southeast Asian foreign affairs target.
Chinese-nexus intrusion set referenced for overlap with Cluster Alpha through shared malware families and C2 infrastructure, previously reported targeting an ASEAN member’s foreign affairs ministry.
Intrusion set associated with the BLOODALCHEMY backdoor, which uses DLL sideloading, shellcode injection, multiple persistence mechanisms, and several communication options. The tooling appears modular and still in active development.
State-sponsored, espionage-motivated intrusion set targeting governments and multinational government organizations in Southern and Southeastern Asia, including an ASEAN foreign affairs ministry environment. Associated with new malware families EAGERBEE, RUDEBIRD, and DOWNTOWN, and assessed as a China-nexus actor.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.