Operation Wocao last observed
The campaign source marks this as the latest known activity date.
Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.
Security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Operation Wocao was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.
Each relationship retains its own confidence and source.
Every date says what it measures so catalog dates are not confused with publication dates.
CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.
Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.
No linked CVEs are available.
No linked techniques are available.
No linked malware or tools are available.
No source-linked indicators are available.
Open the original material before making an attribution or response decision.