CL-UNK-1068: China-Nexus APT Targeting Critical Infrastructure via DLL Sideloading, Xnote Backdoor, ScanPortPlus Scanner, and FRP Tunneling
CL-UNK-1068: China-Nexus APT Targeting Critical (TL-2026-0187), also tracked as CL-UNK-1068, is a high-severity advanced persistent threat campaign, first published 2026-03-06. It is attributed to CL-UNK-1068 (China) with high confidence, affects Microsoft Windows Server, references 2 CVEs (CVE-2021-4034, CVE-2023-34048), maps to 29 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 35 indicators of compromise.
Key facts for TL-2026-0187
- Threat ID
- TL-2026-0187
- Also known as
- CL-UNK-1068
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-03-06
- Last reviewed
- 2026-03-06
- Attribution
- CL-UNK-1068
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- aviation, energy, government, law-enforcement, pharmaceutical, technology, telecommunications
- Target regions
- South Asia, Southeast Asia, East Asia
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in CL-UNK-1068: China-Nexus APT Targeting Critical
Malware and tooling: Xnote, AntSword, Fast Reverse Proxy (FRP), GodZilla, LsaRecorder, ScanPortPlus
Unit 42 identified CL-UNK-1068, a China-nexus threat cluster active since at least 2020, targeting aviation, energy, government, law enforcement, pharmaceutical, technology, and telecommunications sectors across South, Southeast, and East Asia. The group employs cross-platform capabilities including DLL sideloading via python.exe to deploy the Xnote Linux backdoor, custom ScanPortPlus Go-based scanner, and modified Fast Reverse Proxy (FRP) for persistent tunneling, alongside web shells (GodZilla, AntSword), credential theft tools, and privilege escalation exploits.
How CL-UNK-1068: China-Nexus APT Targeting Critical works
CL-UNK-1068 is a previously undocumented Chinese threat activity cluster tracked by Unit 42. Attribution to a Chinese threat actor is assessed with high confidence based on tool provenance from Chinese security communities, linguistic artifacts in configuration files (e.g., FRP authentication token 'frpforzhangwei' referencing a common Chinese name), exclusive use of Xnote malware historically associated with Chinese operators since 2015, and consistent targeting patterns aligned with Chinese strategic intelligence collection priorities.
The group's primary objective is assessed with moderate-to-high confidence to be cyberespionage, although cybercriminal motivation cannot be fully ruled out. Operations have been ongoing since at least 2020, targeting critical infrastructure organizations across South Asia, Southeast Asia, and East Asia.
**Initial Access:** CL-UNK-1068 gains initial access by exploiting public-facing web applications on target servers, subsequently deploying web shells including GodZilla and AntSword variants written in English and Simplified Chinese.
**Post-Compromise Operations:** After establishing initial access, the group executes extensive reconnaissance using batch scripts (hp.bat, hpp.bat) to enumerate user accounts, network configuration, running processes, installed software, security products, connected servers via PuTTY/RDP/VNC history, IIS sites, and Windows Security logs.
**DLL Sideloading:** A key technique involves deploying legitimate Python executables (python.exe, pythonw.exe) alongside a malicious python20.dll loader and obfuscated shellcode files. When the legitimate executable runs, it loads the malicious DLL which decrypts and executes payloads in-memory, delivering ScanPortPlus, FRP, and other tools while evading detection.
**Credential Theft:** The group deploys LsaRecorder (sourced from Chinese Kanxue security forum) to hook the LsaApLogonUserEx2 callback and capture login passwords, Mimikatz for credential dumping, DumpIt with Volatility for extracting NTLM hashes from SAM and cached credentials, and a custom SSMS password export tool.
**Privilege Escalation:** Multiple techniques are employed including PrintSpoofer/PrintProgram exploiting the Windows Print Spooler service, srunas.exe for access token duplication, PwnKit (CVE-2021-4034) on Linux systems, CVE-2023-34048 exploitation against VMware vCenter servers, and Sliver implants with PPID spoofing.
**Persistence and Tunneling:** FRP is deployed with custom authentication tokens and proxy naming conventions (Windows: '10014-win-nic-32-v', Linux: '20012-linux-64-V') using password 'f*ckroot123'. Xnote provides persistent Linux backdoor access with DDoS, file operations, reverse shell, and port forwarding capabilities.
**Data Exfiltration:** Target data includes web application configurations, source code fragments, database backups, credentials from multiple sources, and user documents. Files are archived with WinRAR, Base64-encoded with certutil, and exfiltrated through web shell output. Anti-forensics includes clearing Windows Event logs via wevtutil.
---
**Revalidated on 2026-03-12**
Six days after Unit 42's initial public disclosure on March 6, 2026, CL-UNK-1068 has received widespread industry coverage and validation from major cybersecurity outlets including The Hacker News, Dark Reading, GBHackers, CyberPress, Industrial Cyber, SC Media, Ampcus Cyber, and AboutDFIR. The threat cluster's techniques and tools have been cross-referenced against the broader Chinese cyber-espionage ecosystem, revealing significant overlaps with other documented PRC-aligned operations.
FRP (Fast Reverse Proxy), CL-UNK-1068's primary persistence mechanism, is now tracked by MITRE ATT&CK as Software S1144 and is associated with four threat groups: Volt Typhoon (G1017), Blue Mockingbird (G0108), Magic Hound (G0059), and AppleJeus (G1049). CISA Advisory AA24-038A specifically documented Volt Typhoon's use of obfuscated FRP client files for C2 communications in confirmed compromises of U.S. critical infrastructure, establishing a direct TTP overlap with CL-UNK-1068's modified FRP deployment. The broader Chinese state-sponsored threat landscape was further addressed by CISA Advisory AA25-239A (August 2025), a joint advisory from 19 international agencies documenting PRC actors compromising telecommunications, government, and transportation networks worldwide — sectors that directly overlap with CL-UNK-1068's targeting.
The Xnote backdoor used by CL-UNK-1068 has been confirmed as a shared tool within the Chinese offensive community, previously linked to Earth Berberoka (GamblingPuppet) by Trend Micro for gambling-site targeting. This cross-group tool sharing is consistent with patterns documented across Chinese APT operations, including recent Mustang Panda/Stately Taurus DLL sideloading campaigns against Southeast Asian governments in 2025-2026 and the broader trend of Chinese-aligned groups sharing tooling from forums like Kanxue.
Community Sigma detection rules now cover two of CL-UNK-1068's signature techniques: FRP execution detection (Sigma rule 32410e29, severity HIGH, maps to T1090 Proxy) and Python DLL sideloading detection (Sigma rule d36f7c12, severity MEDIUM, maps to T1574.001). The 2026 Unit 42 Global Incident Response Report, analyzing over 750 major incidents across 50+ countries, confirmed that Chinese-aligned groups are increasingly targeting virtualization platforms and databases with malware designed to hide C2 within legitimate web sessions — a persistence strategy that shares conceptual overlap with CL-UNK-1068's FRP tunneling approach.
No new IOCs, no additional campaigns, and no dedicated government advisory specifically naming CL-UNK-1068 have emerged since the initial disclosure. The threat remains active with the IOCs and infrastructure documented in the original Unit 42 report. Organizations in the targeted sectors (aviation, energy, government, law enforcement, pharmaceutical, technology, telecommunications) across South, Southeast, and East Asia should treat CL-UNK-1068 as an active threat and prioritize monitoring for the specific TTPs and IOCs published by Unit 42.
MITRE ATT&CK techniques used in TL-2026-0187
credential-access
T1003 OS Credential Dumping; T1555 Credentials from Password Stores
collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1560 Archive Collected Data
lateral-movement
T1021 Remote Services; T1570 Lateral Tool Transfer
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1134 Access Token Manipulation; T1140 Deobfuscate/Decode Files or Information
exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
discovery
T1046 Network Service Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
initial-access
T1190 Exploit Public-Facing Application
impact
T1498 Network Denial of Service
persistence
T1505 Server Software Component; T1547 Boot or Logon Autostart Execution
stealth
Affected products and versions in CL-UNK-1068: China-Nexus APT Targeting Critical
- Microsoft — Windows Server
Vulnerable versions: 2016; 2019; 2022 - Microsoft — Windows
Vulnerable versions: 10; 11 - Microsoft — IIS Web Server
Vulnerable versions: All versions - Microsoft — SQL Server (MSSQL)
Vulnerable versions: All versions - Linux — Linux Server
Vulnerable versions: Multiple distributions - VMware — vCenter Server
Vulnerable versions: Pre-patch for CVE-2023-34048
Fixed in: Patched versions
Remediation for CL-UNK-1068: China-Nexus APT Targeting Critical
Patches
- Patch CVE-2021-4034 (PwnKit) on all Linux systems
- Patch CVE-2023-34048 on VMware vCenter Server instances
- Update all public-facing web applications to latest versions
Immediate actions
- Block known C2 IPs at perimeter: 13.250.108.65, 43.255.189.67, 52.77.253.4, 79.141.169.123, 107.148.33.60, 107.148.51.251, 107.148.130.22
- Hunt for python20.dll alongside python.exe/pythonw.exe in non-standard directories
- Scan for GodZilla and AntSword web shells in web server directories (c:\inetpub\wwwroot)
- Monitor for FRP proxy traffic with authentication token 'frpforzhangwei'
- Check for batch scripts (hp.bat, hpp.bat, cl.bat, rar.bat) in system directories
Workarounds
- Disable Network Level Authentication weakening via registry (monitor 3389.bat-style changes)
- Restrict Python executable access to authorized development environments only
- Block certutil -encode operations via endpoint policy where not required
Longer-term hardening
- Deploy EDR with behavioral detection for DLL sideloading and in-memory execution
- Enforce Safe DLL Search Mode and code signing requirements for DLL execution
- Implement application whitelisting to restrict unauthorized executable usage
- Enable MFA on all remote access services (RDP, SSH, VPN)
- Deploy network-based DLP to prevent credential and data exfiltration
- Restrict SQL Server port access (1433/TCP) and disable remote registry access
- Monitor web application directories for unauthorized file creation
CVEs associated with CL-UNK-1068: China-Nexus APT Targeting Critical
Weaknesses (CWE) in CL-UNK-1068: China-Nexus APT Targeting Critical
CWE-426, CWE-269, CWE-78
Timeline of CL-UNK-1068: China-Nexus APT Targeting Critical
- Xnote Linux backdoor (Linux.BackDoor.Xnote.1) first documented by Dr.Web, historically associated with Chinese-speaking threat actors
- LsaRecorder credential hooking utility shared on Chinese Kanxue security forum, later adopted by CL-UNK-1068
- CL-UNK-1068 earliest observed activity begins with deployment of SuperDump .NET reconnaissance tool against critical infrastructure targets
- CVE-2021-4034 (PwnKit) polkit pkexec vulnerability disclosed; CL-UNK-1068 adopts PwnKit.so exploit for Linux privilege escalation
- CVE-2023-34048 VMware vCenter Server out-of-bounds write vulnerability disclosed; CL-UNK-1068 develops Nuitka-compiled Python exploit (vc.exe)
- CL-UNK-1068 evolves from SuperDump to batch script-based reconnaissance (hp.bat, hpp.bat), adopts DLL sideloading via python.exe/python20.dll
- Campaign expands across aviation, energy, government, law enforcement, pharmaceutical, technology, and telecommunications sectors in South/Southeast/East Asia
- Unit 42 (Palo Alto Networks) publicly discloses CL-UNK-1068 activity cluster with comprehensive IOCs and TTP analysis
- Unit 42 publishes comprehensive research report ''An Investigation Into Years of Undetected Operations Targeting High-Value Sectors'' disclosing CL-UNK-1068 for the first time, authored by Tom Fakterman, with full IOC listing, MITRE mappings, and TTP analysis [Source: https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/]
- Threadlinqs Intelligence Platform publishes TL-2026-0187 threat advisory with full MITRE mapping, IOCs, and detection coverage
- Unit 42 (@Unit42_Intel) promotes CL-UNK-1068 research on X/Twitter, highlighting custom malware, modified open-source utilities, and LOLBINs used for persistent access; independent researchers amplify findings [Source: https://x.com/Unit42_Intel/status/2030035719234687198/photo/1]
- Widespread industry coverage amplifies CL-UNK-1068 disclosure: The Hacker News, Dark Reading, GBHackers, CyberPress, Industrial Cyber, Ampcus Cyber ShadowOpsIntel, and AboutDFIR all publish analyses within 72 hours of the Unit 42 report [Source: https://thehackernews.com/2026/03/web-server-exploits-and-mimikatz-used.html]
- As of 2026-05-29, CL-UNK-1068 remains ACTIVE: Unit 42's ~2026-03-09 report describes an ongoing, years-long China-nexus campaign with no disruption, takedown, or successor reported. Its CVE-2023-34048 (VMware vCenter, CVSS 9.8) stays in CISA KEV and is still actively exploited by China-nexus actors into 2026.
Sources cited for CL-UNK-1068: China-Nexus APT Targeting Critical
- Unit 42: CL-UNK-1068 Targets Critical Sectors — Years of Undetected Operations
- Unit 42 Threat Actor Groups Tracked by Palo Alto Networks
- Unit 42 IOC Repository — GitHub
- Dr.Web: Linux.BackDoor.Xnote.1 Malware Description
- MITRE ATT&CK: DLL Side-Loading T1574.002
- MITRE ATT&CK: Network Service Discovery T1046
- Fast Reverse Proxy (FRP) — GitHub Source
- Sliver Adversary Emulation Framework — GitHub
- PwnKit CVE-2021-4034 Exploit — GitHub
- PrintSpoofer Privilege Escalation Tool — GitHub
Threats related to CL-UNK-1068: China-Nexus APT Targeting Critical
Detection coverage for TL-2026-0187
As of 2026-03-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0187 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.