Weaver Ant: The Chinese Cyber Espionage Group That Went Undetected for Four Years

Listen to this Post

A Silent Intruder in Asia’s Telecom Networks

A newly identified China-linked hacking group, Weaver Ant, infiltrated an Asian telecommunications provider and remained undetected for over four years. Cybersecurity firm Sygnia uncovered the group’s existence during an investigation into another cyber threat, shedding light on a sophisticated cyber-espionage operation likely tied to China’s state-backed hackers.

Weaver Ant is suspected of being part of a larger network of espionage groups, including Velvet Ant and Salt Typhoon (also known as Ghost Emperor). These groups primarily target critical infrastructure, using advanced techniques to maintain long-term access and exfiltrate sensitive data.

How Sygnia Discovered Weaver Ant

Sygnia came across Weaver Ant while investigating a separate attack. They noticed unusual activity: an account that had been disabled as part of a previous remediation effort was mysteriously re-enabled by a service account. This activity originated from a server that had not been flagged as compromised before.

A deeper dive revealed a China Chopper web shell on an internal server, which had been exploited for years. Weaver Ant had successfully evaded detection, adapting its techniques to survive multiple cleanup efforts by the company’s security teams.

Several indicators linked the group to China, including:

  • The use of China Chopper web shell variants
  • The presence of Operational Relay Box (ORB) networks
  • The attack patterns aligning with GMT+8 working hours, suggesting a China-based operation

Weaver Ant’s Advanced Tactics and Persistence

To maintain access, Weaver Ant exploited Zyxel Customer Premises Equipment (CPE) routers, using them as an entry point into the telecom provider’s network. Their attack arsenal relied on two primary web shells:

  1. China Chopper (encrypted version) – Used for remote control and undetected payload execution
  2. INMemory web shell – A unique, never-before-seen tool that executes malicious code dynamically, without writing files to disk

These tools allowed Weaver Ant to bypass security measures like Web Application Firewalls (WAFs) and move laterally across the network, infiltrating deeper layers of infrastructure.

The hackers also employed web shell tunneling, a method where multiple web shells act as proxy servers, redirecting traffic and hiding their presence. This enabled them to operate on sensitive internal servers while using public-facing servers as gateways. This technique has previously been observed in other cyber-espionage campaigns, including those conducted by Elephant Beetle.

Challenges in Monitoring Weaver Ant’s Activity

Even after discovering Weaver Ant, Sygnia faced a major challenge: the group was still active within the compromised network. If the hackers noticed the investigation, they might have altered their tactics or gone underground.

To avoid tipping them off, Sygnia used port mirroring and automated decryption techniques instead of deploying security tools directly on infected machines. This stealthy approach allowed Sygnia to monitor Weaver Ant’s movements without alerting them.

Despite

What Undercode Says: Analyzing the Impact of Weaver Ant’s Operations

Weaver Ant’s prolonged infiltration of a telecom company’s network raises critical concerns about cybersecurity in global telecommunications infrastructure. The key takeaways from this case include:

1. Long-Term Cyber Espionage is a Reality

Weaver Ant’s ability to stay hidden for over four years highlights a significant weakness in traditional threat detection. Most security systems are designed to detect and block immediate threats, but stealthy, persistent attackers can still thrive.

2. Advanced Web Shell Techniques Are Evolving

The use of INMemory, a previously unseen web shell, shows that threat actors are innovating faster than cybersecurity defenses. Unlike traditional malware, INMemory operates without leaving disk traces, making detection extremely difficult.

3. Compromising Network Equipment as an Entry Point

Targeting Zyxel CPE routers suggests a strategic shift by hackers: instead of attacking high-security endpoints, they exploit less-secure network devices to gain access. This highlights the need for telecom companies to secure even their low-level infrastructure.

4. Lateral Movement Without Traditional Malware

Weaver Ant’s use of web shell tunneling to move within the network without deploying new malware is an advanced technique that bypasses many endpoint security solutions. This method allows attackers to operate without triggering traditional threat detection mechanisms.

  1. Chinese Cyber Espionage Groups Are Becoming More Sophisticated
    Weaver Ant’s techniques closely resemble those used by other Chinese APT (Advanced Persistent Threat) groups like Velvet Ant and Salt Typhoon. Their coordinated efforts suggest a well-funded, state-backed cyber-espionage program targeting critical industries worldwide.

6. The Difficulty of Full Remediation

Even after detection and mitigation, Weaver Ant was able to reattempt access, proving that removing advanced threat actors is not a one-time fix. Organizations must adopt continuous monitoring and adaptive security measures to stay ahead.

7. Importance of Passive Monitoring in Investigations

Sygnia’s approach—using network traffic analysis instead of

References:

Reported By: https://www.infosecurity-magazine.com/news/china-weaver-ant-hackers-telco/
Extra Source Hub:
https://www.linkedin.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image