Year2022 |
MonthMarch |
Reference number20220301 |
Impact areaOffshore |
Incident locationTaiwan Strait |
Incident countryTaiwan |
Victim countryTaiwan |
Victim identityYunlin offshore wind farm |
Victim TypeOffshore Wind Farm |
MethodPhishing |
Attacker countryChina |
The Chinese state-aligned threat actor TA423 (aka Leviathan/APT40) is behind a sustained cyber-espionage (phishing) campaign, that lasted more than a year, against countries and entities operating in the South China Sea, including organizations involved in an offshore wind farm in the Taiwan Strait. TA423 has been active for almost 10 years, with its activity dovetailing with military and political events in the Asia-Pacific region. TA423's typical targets include defense contractors, manufacturers, universities, government agencies, legal firms involved in diplomatic disputes, and foreign companies involved with Australasian policy or South China Sea operations. TA423 is one of the most consistent advanced persistent threat (APT) actors in the threat landscape, supporting the Chinese government in matters related to the South China Sea, including during the recent tensions in Taiwan.