PRC-Nexus Espionage Actor Exploits GlobalProtect and Abuses Remote Support Tools
A suspected PRC-nexus espionage actor conducted a widespread exploitation campaign targeting the CVE-2026-0257 vulnerability in GlobalProtect VPN portals. The campaign involved advanced evasion and privilege escalation techniques, including the disabling of security controls such as Duo multi-factor authentication. The threat actor used remote support tools to maintain access and further compromise systems. The campaign has been active since early June 2026 and has targeted multiple industries and countries globally.
- First seen
- 2026-03-04
- Last seen
- 2026-09-25
- Threat actors
- UNC6779
- Malware
- SNOWLIGHT
- Sectors
- Automotive, Non-profit & NGO, Construction & Real Estate, Education & Research, Energy & Utilities, Financial Services, Government, Healthcare & Pharmaceuticals
- Countries
- ES, CZ, US, FR, GE, BR, IN, GB
How it works
The campaign began with exploitation of the CVE-2026-0257 vulnerability in GlobalProtect, allowing initial access. Once inside, the actor used remote support tools to move laterally and execute commands. Security controls were disabled to evade detection, and privilege escalation was performed to gain deeper access. The threat actor then exfiltrated data and maintained persistence through remote access methods.
Techniques (MITRE ATT&CK)
- T1016 · Initial AccessPhishingThe threat actor may have used phishing emails to deliver malicious payloads or gain initial access to systems.
- T1021 · Initial AccessValid AccountsThe actor likely used stolen or compromised credentials to access systems, leveraging valid user accounts for initial entry.
- T1021.001 · Credential AccessBrute ForceBrute force attacks may have been used to guess passwords and gain access to systems or accounts.
- T1021.002 · Credential AccessPassword SprayingThe actor may have used password spraying techniques to bypass authentication mechanisms and gain access to systems.
- T1021.006 · Initial AccessInput ValidationExploitation of the CVE-2026-0257 vulnerability involved improper input validation to gain unauthorized access to the GlobalProtect portal.
- T1027 · Defense EvasionIndicator Removal on the HostThe threat actor removed or altered logs and indicators to avoid detection by security systems.
- T1033 · Privilege EscalationAccount ManipulationThe actor manipulated user accounts to elevate privileges and gain administrative access to systems.
- T1036 · Defense EvasionMasqueradingThe threat actor used masquerading techniques to disguise malicious activities as legitimate system processes or user actions.
- T1036.004 · Defense EvasionMasquerading - Remote ServicesThe actor used remote support tools to mimic legitimate remote access services, making it difficult to detect malicious activity.
- T1049 · Command and ControlWindows Remote ManagementThe actor used Windows Remote Management to establish and maintain remote control over compromised systems.
- T1053 · PersistenceModification of Existing CodeThe threat actor modified existing code on the system to maintain long-term access and control over the compromised environment.
- T1053.005 · PersistenceScheduled Task/JobThe actor created scheduled tasks or jobs to ensure continued access and execution of malicious payloads at regular intervals.
- T1057 · PersistenceBoot or Logon Initialization ScriptsThe threat actor may have used boot or logon scripts to execute malicious code during system startup or user logon.
- T1059 · ExecutionCommand and Scripting InterpreterThe actor used command-line interpreters to execute malicious scripts and commands on compromised systems.
Indicators
Indicators associated with this campaign in the sources we reviewed. Corroborate before blocking: an address or domain can be shared infrastructure.
- 49c8909f545af6b47b9331d64a2881742065542ca8b8e9b7a0b1e40cf62bf477
- 7b60aafdaf244349b03c148e1acde0dc
- adminapi.googledocmentcenter.top
- document.googledocmentcenter.top
- document.spacexonline.com
- googledocmentcenter.top
- member.googledocmentcenter.top
- member.spacexonline.com
- spacexonline.com
- update.googledocmentcenter.top
- update.spacexonline.com
- www.googledocmentcenter.top
- 134.82.68.30
- 188.214.106.179
- 188.214.106.181
- 23.234.101.103
- 45.152.65.134
- 47.245.56.91
- 47.76.138.131
- 47.79.151.176
- 47.79.32.81
- 47.79.34.55
- 47.79.87.7
- 47.83.11.151
- 48.210.26.97
- 8.210.131.228
- 99.88.87.227
- http://document.spacexonline.com:443/functionalStatus/
- http://document.spacexonline.com/
What to do
- Apply patches for CVE-2026-0257 immediately to mitigate initial access vectors.
- Implement multi-factor authentication and ensure it is not easily disabled by unauthorized users.
- Monitor for unusual activity related to remote support tools and ensure they are only used by authorized personnel.
- Conduct regular audits of system logs and user accounts to detect unauthorized changes or privilege escalations.
- Deploy endpoint detection and response (EDR) solutions to detect and respond to advanced evasion techniques.
- Use network traffic analysis to identify anomalous communication patterns, such as those associated with command and control servers.