logo

Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets

ID: 8b476401-ef9f-4248-a34c-520f5909f0b1

STIX ID: report--8b476401-ef9f-4248-a34c-520f5909f0b1

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2022-09-22

Last Modified Date: 2022-09-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future assesses that TA413, a likely Chinese state-sponsored actor, has actively targeted Tibetan-affiliated organizations in 2022 using both shared tooling (Royal Road RTF) and rapidly adopted zero-day exploits (Sophos Firewall CVE-2022-1040 and MSDT 'Follina' CVE-2022-30190) to deliver a custom backdoor named LOWZERO; the report provides detailed LOWZERO malware analysis, C2 protocol weaknesses, TTP mapping, and extensive IOCs to support detection and mitigation.