By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Life Care NewsLife Care NewsLife Care News
  • Home
  • Business
    • Business
  • News
  • Tech
  • Entertainment
  • Health
  • Education
  • Automobile
  • Sports
Search
Technology
  • Advertise
  • Advertise
Health
Entertainment
  • Home
  • Business
    • Business
  • News
  • Tech
  • Entertainment
  • Health
  • Education
  • Automobile
  • Sports
  • Advertise
  • Advertise
Copyright © 2015 - 2024 LifeCareNews Network. All Rights Reserved.
LIFE CARE IS REGISTERED MAGAZINE IN RNI, NO.GUJGUJ/2015/71283
Reading: Sygnia Discovers New Active China-Nexus Threat Actor Weaver Ant
Share
Notification Show More
Font ResizerAa
Life Care NewsLife Care News
Font ResizerAa
  • Education
  • Automobile
  • Entertainment
  • News
  • Tech
  • Sports
Search
  • Home
  • Home
    • Home 1
    • Default Home 5
  • Categories
  • Categories
    • Tech
    • Entertainment
    • Automobile
    • Sports
    • Education
    • News
    • Health
  • Bookmarks
  • Bookmarks
  • More Foxiz
    • Sitemap
  • More Foxiz
    • Sitemap
Follow US
  • Advertise
  • Advertise
Copyright © 2015 - 2024 LifeCareNews Network. All Rights Reserved. LIFE CARE IS REGISTERED MAGAZINE IN RNI, NO.GUJGUJ/2015/71283
Business

Sygnia Discovers New Active China-Nexus Threat Actor Weaver Ant

Business Wire
Last updated: 24/03/2025 2:54 PM
Business Wire
Share
4 Min Read
Sygnia Discovers New Active China-Nexus Threat Actor Weaver Ant
SHARE
Sygnia Discovers New Active China-Nexus Threat Actor Weaver Ant

Incident Response leader reveals Weaver Ant leveraged home routers to target top telecoms company and collect sensitive information

TEL-AVIV, Israel & NEW YORK–(BUSINESS WIRE)–Sygnia, the foremost global cyber readiness and response team, revealed today a new China nexus threat actor, which the company has named Weaver Ant. To infiltrate the telecom company and gain access to sensitive data, Weaver Ant compromised Zyxel CPE home routers as an entry point into the victim’s network. The APT also utilized a new web shell, dubbed “INMemory” to enable in-memory execution of malicious modules while evading detection.




As part of Sygnia’s investigation into a separate threat actor, an account that was disabled by initial remediation efforts was re-enabled by a service account. Upon investigation, Sygnia determined that the account had been previously used by Weaver Ant. Notably, the activity originated from a server that had not been previously identified as compromised. This prompted a large-scale forensic investigation and as a result, Sygnia uncovered a variant of the China Chopper Web shell deployed on an internal server that had been compromised for several years.

- Advertisement -

“Nation-state threat actors like Weaver Ant are incredibly dangerous and persistent with the primary goal of infiltrating critical infrastructure and collecting as much information as they can before being discovered,” said Oren Biderman, Incident Response and Digital Forensic Team Leader at Sygnia. “Multiple layers of web shells concealed malicious payloads, allowing the threat actor to move laterally within the network and remain evasive until the final payload. These payloads and their ability to leverage never-seen-before web shells to evade detection speaks to Weaver Ant’s sophistication and stealthiness.”

How Weaver Ant Tunneled into Telco

The web shell hunt revealed two types of web shells in different variants. The first was classified by Sygnia as an encrypted China Chopper. China Chopper enabled Weaver Ant to gain remote access and control of web servers. Notably, variants of the China Chopper web shell support AES encryption of a payload, making it highly effective at evading detection at the Web Application Firewall level.

The second web shell, INMemory was discovered by Sygnia and had no publicly available references to any other known web shells. INMemory’s leveraged just-in-time (JIT) compilation and execution of code at runtime to dynamically execute malicious payloads without having to write them onto the disk.

Biderman added, “Weaver Ant maintained activity within the compromised network for over four years despite repeated attempts to eliminate them from compromised systems. The threat actor adapted their TTPs to the evolving network environment, enabling continuous access to compromised systems and the collection of sensitive information.”

- Advertisement -

Following the investigation and an extensive eradication effort, Sygnia continues to monitor Weaver Ant. The threat actor has already been detected attempting to regain access to the telecom company’s network.

For the complete details, please see the associated report and technical annex.

About Sygnia

- Advertisement -

Sygnia is the world’s foremost cyber response and readiness expert. It applies creative approaches and bold solutions to each phase of an organization’s security journey, meeting them where they are to ensure cyber resilience. Sygnia is the trusted advisor and service provider of leading organizations worldwide, including Fortune 100 companies. Sygnia is a Temasek company, part of the ISTARI Collective. For more about Sygnia, visit Sygnia.co.

Contacts

Kathryn Thompson Dossey

Global Communications Manager

Media@sygnia.co
+1 704-776-8127

You Might Also Like

Securities Fraud Investigation Into Ibotta, Inc. (IBTA) Announced Investors Who Lost Money Urged to Contact Glancy Prongay & Murray LLP, a Leading Securities Fraud Law Firm

Ascend produces bio-circular performance chemicals, PA66

Sendai Isawa Family Katsuyama Sake Brewery: SAMURAI SAKE: Reviving a 300-Year-Old Recipe

Phoenix Aviation Capital Acquires One Airbus A321neo Aircraft on Lease with IndiGo

Next Wave of Leading Women in AI Identified in New Global Data Set

TAGGED:accountactorantchinacollectcompanycompromisedhomeincidentinformationinmemoryinvestigationisraelleaderleveragedpreviouslyresponserevealsrouterssensitiveservershellsygniatelavivtelecom’sthreattopweaverwebyorkbusiness

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Copy Link Print
Share
Previous Article 3D Investment Partners Reminds Sapporo Shareholders to Vote FOR the Appointment of Paul Brough at Sapporos Upcoming AGM to Enhance Board Oversight 3D Investment Partners Reminds Sapporo Shareholders to Vote FOR the Appointment of Paul Brough at Sapporos Upcoming AGM to Enhance Board Oversight
Next Article Clearspeed Partners with 1st Central to Transform Its Insurance Claims Experience Clearspeed Partners with 1st Central to Transform Its Insurance Claims Experience

Stay Connected

FacebookLike
TwitterFollow
PinterestPin
InstagramFollow
YoutubeSubscribe
Google NewsFollow
LinkedInFollow
MediumFollow
- Advertisement -

Latest News

Knest Onboards Lighthouse Funds as a Strategic Partner, Secures a landmark 300 Crore Backing
Knest Onboards Lighthouse Funds as a Strategic Partner, Secures a landmark 300 Crore Backing
Tech 20/06/2025
“We Now Need to Create Opportunities Across Sectors” – UK Minister Patrick Vallance Urges Deeper UK-India Science Partnerships
“We Now Need to Create Opportunities Across Sectors” – UK Minister Patrick Vallance Urges Deeper UK-India Science Partnerships
Tech 20/06/2025
SBI Life crowdsources future-facing AI solutions from India’s Next-Gen Talent pool at the 2025 Hack-AI-Thon finale
SBI Life crowdsources future-facing AI solutions from India’s Next-Gen Talent pool at the 2025 Hack-AI-Thon finale
Tech 20/06/2025
SAINT-GOBAIN ENHANCES ITS DIGITAL CONSTRUCTION CHEMICALS PLATFORM WITH THE ACQUISITION OF MATURIX
SAINT-GOBAIN ENHANCES ITS DIGITAL CONSTRUCTION CHEMICALS PLATFORM WITH THE ACQUISITION OF MATURIX
Tech 20/06/2025
//

We increase the awareness of millions of users through our news networks. We are one of the most trusted news networks in the world.

Quick Link

  • About Us
  • Contact Us
  • Editorial Guidelines
  • Privacy Policy
  • Terms and Conditions

Top Categories

  • Automobile
  • Education
  • Entertainment
  • Health
  • News
  • Sports
  • Tech

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

Life Care NewsLife Care News
Follow US
Copyright © 2015 - 2024 LifeCareNews Network. All Rights Reserved. LIFE CARE IS REGISTERED MAGAZINE IN RNI, NO.GUJGUJ/2015/71283
Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?