Home/Threat Actor/Worok
Threat Actor

Worok

worok · china · active since 2020-late

Worok (canonical ESET naming per Thibaut Passilly's September 6, 2022 disclosure "Worok: the big picture") is a suspected People's Republic of China state-aligned cyber-espionage cluster active publicly since at least late 2020 with primary operational mission objectives of intelligence collection from high-profile companies and local governments mostly in Asia (East Asia, Central Asia, Southeast Asia) with secondary targeting in Middle East and southern Africa.

operationally distinct from 33 China- attributed clusters already curated through signature CLRLoad - PowHeartBeat PowerShell backdoor - PNGLoad multi-stage execution chain, signature PNG-file-steganography payload- extraction operational tradecraft (PNGLoad uses Bitmap objects in C# taking pixel information without metadata to conceal malicious payloads in valid innocuous PNG images "hiding in plain sight"), signature multi-regional target- set spanning Asia + Middle East + Africa, and ProxyShell- era operational emergence pattern.

ESET-noted operational tradecraft overlap with TA428 (Chinese state-sponsored cluster also known as Colorful Panda) including common activity times, targeted verticals, and ShadowPad backdoor use, but Worok tracked as distinct cluster from TA428; signature tooling evolution from CLRLoad (2021 C++ first- stage loader) to PowHeartBeat (2022+ PowerShell full- featured backdoor with multi-layer obfuscation including Triple DES CBC mode encryption + gzip compression) launching PNGLoad C# .NET steganographic loader.

ProxyShell (CVE- 2021-34523 + CVE-2021-34473 + CVE-2021-31207) Microsoft Exchange Server vulnerability chain exploitation.

publicly- available reconnaissance tooling includes Mimikatz + EarthWorm + ReGeorg + NBTscan.

PowHeartBeat communicates via HTTP initially and ICMP in version 2.4+.

operational dormancy period May 2021 - January 2022 followed by February 2022 resurgence.

targeted sectors include telecommunications + banking + maritime industry + energy + military + government + public sector.

34th China-attributed cluster in the curated corpus.

china confidence: high 6 aliases

Profile

Worok (canonical ESET naming Worok per Thibaut Passilly's September 6, 2022 disclosure titled "Worok: the big picture") is a suspected People's Republic of China state- aligned cyber-espionage cluster active publicly since at least late 2020. The cluster's primary operational mission objectives are intelligence collection from high-profile companies and local governments mostly in Asia, with secondary targeting in the Middle East and Africa. ESET assesses "Worok's main objective is to steal information" and operationally categorizes the cluster as a cyber- espionage group developing its own tools and leveraging existing tools to compromise targets.

The cluster is operationally distinct from the 33 China- attributed clusters already curated in this corpus through three signature operational-pattern features: (1) Signature CLRLoad
  • PowHeartBeat.
  • PNGLoad multi- stage execution chain. Operational tooling evolution from CLRLoad (2021 first-stage C++ PE loader) to PowHeartBeat (2022 PowerShell full-featured backdoor replacement), followed by PNGLoad (C# .NET 64-bit steganographic loader) as second-stage payload. (2) Signature PNG-file-steganography payload-extraction operational tradecraft. PNGLoad uses Bitmap objects in C# that take only pixel information from PNG files, enabling concealment of malicious payloads in valid innocuous-looking PNG images "hiding in plain sight." (3) Signature target-set spanning Asia + Middle East + Africa. The cluster's multi-regional targeting pattern operationally distinguishes Worok from competing China- aligned clusters with narrower regional focus. Operational phases: (1) Operational emergence era (Late 2020). Earliest observed targets: telecommunications (East Asia), banking (Central Asia), maritime industry (Southeast Asia), government entity (Middle East), private company (southern Africa). (2) ProxyShell-era operational emergence (Early 2021). During the ProxyShell (CVE-2021-34523) Microsoft Exchange Server vulnerability disclosure era, Worok emerged among various APT groups exploiting the vulnerability chain. Operational tradecraft overlap with TA428 noted by ESET, common activity times, targeted verticals, ShadowPad backdoor, but Worok tracked as distinct cluster. (3) Operational dormancy period (May 2021.
  • January 2022). Approximately 8 months of operational dormancy, operationally distinctive among Chinese-state-aligned clusters of the era. (4) February 2022 operational resurgence + tooling evolution era. Cluster operations resumed with new targets (energy company in Central Asia, public sector entity in Southeast Asia) and tooling evolution from CLRLoad to PowHeartBeat. (5) ESET canonical disclosure (September 6, 2022). ESET researcher Thibaut Passilly published canonical cluster disclosure on WeLiveSecurity. (6) Continued operations (2022-2026). Sustained operational tempo with incremental tooling updates.
Signature operational tradecraft
  • CLRLoad first-stage C++ PE loader (2021 era): generic Windows PE that loads the next stage (PNGLoad), which must be a Common Language Runtime (CLR) assembly DLL.
  • PowHeartBeat full-featured PowerShell backdoor (2022+ era): replaced CLRLoad as the tool used to launch PNGLoad. Sophisticated multi-layer obfuscation: base64- encoded PowerShell chunks.
  • IEX execution.
  • base64-decoded.
  • Triple DES (CBC mode) decrypted.
  • gzip decompressed.
  • third-layer actual backdoor PowerShell code. Capabilities: command/process execution, file manipulation, configuration update, encrypted logs, C2 via HTTP (initial versions) or ICMP (version 2.4+).
  • PNGLoad C# .NET steganographic loader (signature): 64-bit .NET executable obfuscated with .NET Reactor that masquerades as legitimate software via placement in legitimate directories. Uses steganography to extract hidden malicious payloads from PNG files, Bitmap objects in C# take pixel information without metadata, enabling concealment in valid innocuous PNG images.
  • ProxyShell exploitation initial-access: CVE-2021- 34523 + CVE-2021-34473 + CVE-2021-31207 Microsoft Exchange Server vulnerability chain exploitation noted by ESET in "select instances" of 2021 and 2022 initial-access operations.
  • Publicly-available reconnaissance tooling: Mimikatz (credential dumping), EarthWorm (network tunneling), ReGeorg (SOCKS tunneling), NBTscan (network reconnaissance).
  • ShadowPad backdoor operational overlap with TA428: tooling overlap noted by ESET but cluster tracked as distinct from TA428 / Colorful Panda based on differences in remaining tooling (TA428's Able Desktop compromise 2020 not shared by Worok).
  • HTTP + ICMP dual-protocol C2 communication: PowHeartBeat communicates with C2 server initially over HTTP and later (version 2.4+) via ICMP, operationally providing C2 communication flexibility and evading network- detection signatures focused on HTTP-only patterns. The cluster fills the multi-regional-targeting steganography- specialized China-aligned APT cell in this curated corpus (now 34 China-attributed clusters total, earth_krahang brought to 33 in v0.1.104, worok brings to 34 in v0.1.105). Worok is operationally distinct from competing China- attributed clusters through signature PNG-steganography payload-extraction tradecraft, signature multi-regional targeting spanning Asia + Middle East + Africa, ProxyShell- era operational emergence pattern, and signature CLRLoad.
  • PowHeartBeat.
  • PNGLoad multi-stage execution chain.

Aliases

6
worokworok aptworok_chinaworok_apt_clusterta428 overlapcolorful panda overlap

Notable Campaigns

9
2023-2026Continued Operations Through 2023-2026
2022-PresentPowHeartBeat Multi-Layer Obfuscation Architecture
2022February 2022 Operational Resurgence
2022ESET Canonical Worok Disclosure (September 6, 2022)
2021-PresentPNGLoad Steganography Operational Tradecraft (Signature)
2021-2022Operational Dormancy Period (May 2021 - January 2022)
2021-2022CLRLoad to PowHeartBeat Tooling Evolution (2021 - 2022)
2021ProxyShell Era Operational Emergence (Early 2021)
2020Worok Operational Emergence (Late 2020)

Attribution & Reporting

Attributed by
ESETMandiantMicrosoft Threat Intelligence CenterProofpointCybereasonCrowdStrikeRecorded Future Insikt GroupTrend MicroSOPHOS X-OpsSymantec / Broadcom Threat Hunter TeamSentinelOne / SentinelLabsKPMG Cyber Threat Intelligence
Key reporting
reportESET (Thibaut Passilly): Worok, the big picture (September 6, 2022), canonical comprehensive Worok cluster disclosure
reportESET India Press Release: ESET Research uncovers new cyberespionage group Worok targeting companies, governments mostly in Asia (September 6, 2022)
reportThe Hacker News (Ravie Lakshmanan): Worok Hackers Target High-Profile Asian Companies and Governments (September 6, 2022)
reportSecurityWeek (Ionut Arghire): New Cyberespionage Group 'Worok' Targeting Entities in Asia
reportThe Register: Newly Discovered Cyberspy Group Targets Asia (September 6, 2022)
reportIndustrial Cyber: ESET Details Worok Cyberespionage Group Targeting Asian Governments, Corporations (September 7, 2022)
reportKPMG India Cyber Threat Intelligence Notification: Worok Hacker Targets Government and Critical Organizations Across Asia (September 19, 2022)
reportMandiant: China-Nexus Cluster Tracking, Worok Adjacent Activity
reportMicrosoft Threat Intelligence: China-Aligned Cluster Tracking
reportProofpoint: TA428 Continued Tracking (Worok operational overlap context)
reportCybereason: TA428 / Colorful Panda Tracking
reportCrowdStrike Global Threat Report: China State-Aligned Cluster Tracking
reportRecorded Future Insikt Group: China State-Aligned Cyber-Espionage Tracking
reportTrend Micro: Asia-Targeting Cluster Tracking
reportSOPHOS X-Ops: China-Nexus APT Cluster Tracking
reportSymantec / Broadcom Threat Hunter Team: China-Aligned APT Continued Tracking
reportSentinelLabs: China-Nexus Cluster Operational Analysis
reportMITRE ATT&CK Group G1018, Worok
reportMalpedia Actor Profile: Worok

Operational

State sponsor

Suspected People's Republic of China state-aligned cyber- espionage cluster. ESET researchers (lead: Thibaut Passilly) tracked Worok as a previously-undocumented cyber-espionage group in the canonical September 6, 2022 disclosure titled "Worok: the big picture." ESET assessment notes: "Worok is a cyber espionage group that develops its own tools, as well as leveraging existing tools, to compromise its targets. Considering the targets' profiles and the tools we've seen deployed against these victims, we think Worok's main objective is to steal information." The China- alignment attribution is operationally supported by (a) operational tradecraft overlap with TA428 (a Chinese state- sponsored cluster also known as Colorful Panda per Proofpoint / Cybereason tracking) including "common activity times, targeted verticals, and the use of ShadowPad backdoor"; (b) targeting pattern operationally aligned with broader Chinese-state-aligned strategic intelligence-collection priorities (high-profile companies and local governments mostly in Asia, with extensions to Middle East and Africa); (c) operational emergence coinciding with the early-2021 ProxyShell (CVE-2021-34523) vulnerability disclosure era, operationally consistent with broader Chinese-state-aligned APT cluster ProxyShell-era operational opportunism patterns including HAFNIUM / Silk Typhoon (curated separately as silk_typhoon.yaml).

ESET assesses "We consider that the links are not strong enough to consider Worok to be the same group as TA428, but the two groups might share tools and have common interests", operationally tracking Worok as a distinct cluster from TA428 despite tradecraft overlap. The cluster is operationally distinct from the 33 China- attributed clusters already curated in this corpus (including chimera_china and earth_krahang from this turn's v0.1.102 + v0.1.

104 additions) through (a) signature PNG- file-steganography payload-extraction operational tradecraft (PNGLoad component); (b) signature CLRLoad
  • PowHeartBeat.
  • PNGLoad multi-stage execution chain; (c) signature target-set spanning Asia + Middle East + Africa with specific targeting of telecommunications + banking + maritime + energy + government sectors; (d) ProxyShell-era operational emergence pattern. No formal Chinese government attribution has been asserted by any government cyber- security authority, ESET tracks the cluster at the broader "cyber espionage group" level with operational overlap to TA428.
Motivations
cyber_espionage_intelligence_collection, information_theft, chinese_state_aligned_strategic_intelligence_collection, asia_regional_intelligence_collection, telecommunications_industry_intelligence, financial_industry_intelligence, maritime_industry_intelligence, energy_industry_intelligence, government_sector_intelligence
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)54/60 · 90%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin