CeranaKeeper — APT Profile

CeranaKeeper is a China-aligned cyberespionage APT first documented by ESET in October 2024, active since at least early 2022. It has targeted governmental institutions across Southeast and East Asia, most heavily Thailand, along with Myanmar, the Philippines, Japan, and Taiwan, conducting what ESET describes as massive-scale data exfiltration from Thai government networks starting in 2023. The group is distinguished by heavy abuse of legitimate cloud and file-sharing services — Dropbox, OneDrive, GitHub, Pastebin, and PixelDrain — as covert command-and-control and exfiltration channels, including a technique (BingoShell) that turns GitHub pull-request and issue-comment functions into a hidden reverse shell. Its toolset includes the TONESHELL, TONEINS, and PUBLOAD backdoors alongside newer custom tools (WavyExfiller, DropboxFlop, OneDoor) and DLL side-loading for delivery. ESET named the group after the Asian honeybee Apis cerana, a wordplay on the string "bectrl" found repeatedly in its code. Although some early components overlap with tooling previously attributed to Mustang Panda, ESET assesses CeranaKeeper as operationally and technically distinct from that group.

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions