BRONZE PRESIDENT is a likely People’s Republic of China (PRC)-based targeted cyber espionage group that uses both proprietary and publicly available tools to target NGO networks. Collected evidences indicate that network intrusions by this threat group may date back to 2014. The BRONZE PRESIDENT cyber espionage group targets NGOs, as well as political and law enforcement organizations in countries in South and East Asia. The threat group appears to have developed its own remote access tools that it uses alongside publicly available remote access and post-compromise tool-sets. After compromising a network, the threat actors elevate their privileges and install malware on a large proportion of systems. The group runs custom batch scripts to collect specific file types and takes proactive steps to minimize detection of its activities.
Block the threat indicators at their respective controls.