Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets
ID: 8b476401-ef9f-4248-a34c-520f5909f0b1
STIX ID: report--8b476401-ef9f-4248-a34c-520f5909f0b1
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2022-09-22
Last Modified Date: 2022-09-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future assesses that TA413, a likely Chinese state-sponsored actor, has actively targeted Tibetan-affiliated organizations in 2022 using both shared tooling (Royal Road RTF) and rapidly adopted zero-day exploits (Sophos Firewall CVE-2022-1040 and MSDT 'Follina' CVE-2022-30190) to deliver a custom backdoor named LOWZERO; the report provides detailed LOWZERO malware analysis, C2 protocol weaknesses, TTP mapping, and extensive IOCs to support detection and mitigation.
