CL-UNK-1068: China-Nexus APT Targeting Critical Infrastructure via DLL Sideloading, Xnote Backdoor, ScanPortPlus Scanner, and FRP Tunneling — Threadlinqs Intelligence
As of 2026-05-30, CL-UNK-1068: China-Nexus APT Targeting Critical Infrastructure via DLL Sideloading, Xnote Backdoor, ScanPortPlus Scanner, and FRP Tunneling is a high-severity apt threat attributed to CL-UNK-1068 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-0187 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: CL-UNK-1068 · China · ESPIONAGE
Unit 42 identified CL-UNK-1068, a China-nexus threat cluster active since at least 2020, targeting aviation, energy, government, law enforcement, pharmaceutical, technology, and telecommunications
CL-UNK-1068 is a previously undocumented Chinese threat activity cluster tracked by Unit 42. Attribution to a Chinese threat actor is assessed with high confidence based on tool provenance from Chinese security communities, linguistic artifacts in configuration files (e.g., FRP authentication token 'frpforzhangwei' referencing a common Chinese name), exclusive use of Xnote malware historically associated with Chinese operators since 2015, and consistent targeting patterns aligned with Chinese strategic intelligence collection priorities.
The group's primary objective is assessed with moderate-to-high confidence to be cyberespionage, although cybercriminal motivation cannot be fully ruled out. Operations have been ongoing since at least 2020, targeting critical infrastructure organizations across South Asia, Southeast Asia, and East Asia.
**Initial Access:** CL-UNK-1068 gains initial access by exploiting public-facing web applications on target servers, subsequently deploying web shells including GodZilla and AntSword variants written in English and Simplified Chinese.
**Post-Compromise Operations:** After establishing initial access, the group executes extensive reconnaissance using batch scripts (hp.bat, hpp.bat) to enumerate user accounts, network configuration, running processes, installed software, security products, connected servers via PuTTY/RDP/VNC history, IIS sites, and Windows Security logs.
**DLL Sideloading:** A key technique involves deploying legitimate Python executables (python.exe, pythonw.exe) alongside a malicious python20.dll loader and obfuscated shellcode files. When the legitimate executable runs, it loads the malicious DLL which decrypts and executes payloads in-memory, delivering ScanPortPlus, FRP, and other tools while evading detection.
**Credential Theft:** The group deploys LsaRecorder (sourced from Chinese Kanxue security forum) to hook the LsaApLogonUserEx2 callback and capture login passwords, Mimikatz for credential dumping, DumpIt with Volatility for extracting NTLM hashes from SAM and cached credentials, and a custom SSMS password export tool.
**Privilege Escalation:** Multiple techniques are employed including PrintSpoofer/PrintProgram exploiting the Windows Print Spooler service, srunas.exe for access token duplication, PwnKit (CVE-2021-4034) on Linux systems, CVE-2023-34048 exploitation against VMware vCenter servers, and Sliver implants with PPID spoofing.
**Persistence and Tunneling:** FRP is deployed with custom authentication tokens and proxy naming conventions (Windows: '10014-win-nic-32-v', Linux: '20012-linux-64-V') using password 'f*ckroot123'. Xnote provides persistent Linux backdoor access with DDoS, file operations, reverse shell, and port forwarding capabilities.
**Data Exfiltration:** Target data includes web application configurations, source code fragments, database backups, credentials from multiple sources, and user documents. Files are archived with WinRAR, Base64-encoded with certutil, and exfiltrated through web shell output. Anti-forensics includes clearing Windows Event logs via wevtutil.
---
**Revalidated on 2026-03-12**
Six days after Unit 42's initial public disclosure on March 6, 2026, CL-UNK-1068 has received widespread industry coverage and validation from major cybersecurity outlets including The Hacker News, Dark Reading, GBHackers, CyberPress, Industrial Cyber, SC Media, Ampcus Cyber, and AboutDFIR. The threat cluster's techniques and tools have been cross-referenced against the broader Chinese cyber-espionage ecosystem, revealing significant overlaps with other documented PRC-aligned operations.
FRP (Fast Reverse Proxy), CL-UNK-1068's primary persistence mechanism, is now tracked by MITRE ATT&CK as Software S1144 and is associated with four threat groups: Volt Typhoon (G1017), Blue Mockingbird (G0108), Magic Hound (G0059), and AppleJeus (G1049). CISA Advisory AA24-038A specifically documented Volt Typhoon's use of obfuscated FRP client files for
Weaknesses (CWE)
CWE-426, CWE-269, CWE-78
Target sectors: aviation, energy, government, law-enforcement, pharmaceutical, technology, telecommunications
Target regions: South Asia, Southeast Asia, East Asia
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2021-4034, CVE-2023-34048, T1190, T1505, T1547, T1574, T1068, T1134, T1574, T1027, T1140, T1070