Watering Hole Attacks Push ScanBox Keylogger

A sophisticated cyber-espionage campaign originating from China has once again brought state-sponsored threat groups into the international spotlight. According to a joint intelligence report released by cybersecurity firms Proofpoint and PricewaterhouseCoopers (PwC), a threat actor designated as TA423—also widely known as Red Ladon—has been actively deploying the ScanBox JavaScript reconnaissance framework. The campaign, which researchers observed running from April through mid-June 2022, primarily targeted domestic Australian organizations as well as offshore energy firms operating within the contested waters of the South China Sea.
The operation relied on a combination of targeted spear-phishing lures and compromised websites, often referred to as watering holes. By leveraging seemingly innocuous topics such as corporate leave requests and collaborative research initiatives, the attackers successfully redirected high-profile targets to fraudulent news portals designed to harvest sensitive data and profile victim systems silently. Despite prior international law enforcement actions and public indictments against its members, the latest intelligence indicates that TA423 continues to operate with an undiminished operational tempo, aligning its cyber intelligence-gathering activities closely with broader geopolitical objectives set by Beijing.
Anatomy of the Campaign and the Watering Hole Delivery Mechanism
The cyber-espionage campaign kicked off in early spring 2022, utilizing a meticulously orchestrated multi-stage delivery pipeline. The initial phase of the attack vector depended heavily on social engineering via email. Threat actors distributed spear-phishing messages carrying thematic titles designed to provoke curiosity or a sense of administrative obligation among corporate and government employees. Subject lines such as "Sick Leave," "User Research," and "Request Cooperation" were deployed to maximize click-through rates.
These emails typically purported to originate from employees of a fabricated media outlet named "Australian Morning News" (hosted on the domain australianmorningnews[.]com). Recipients were politely urged to visit the platform to review newly published content relevant to regional affairs.
When a targeted individual clicked the link embedded within the phishing email, they were redirected to an external web page that mirrored legitimate, mainstream news aggregators like the BBC and Sky News. However, unknown to the visitor, the site was laden with malicious code. Behind the scenes, the compromised or spoofed webpage executed the ScanBox framework—a multifunctional, JavaScript-based reconnaissance tool that has been utilized by various cyber criminal and state-sponsored syndicates for nearly a decade.
Unlike traditional malware payloads that must be written to a target’s hard disk to be effective, ScanBox operates entirely within the memory of the web browser. This "fileless" characteristic makes it notoriously difficult for conventional endpoint detection and response (EDR) agents to flag immediately upon execution. Once loaded, the script immediately begins harvesting intelligence on the visitor through a process known as browser fingerprinting.
Technical Capabilities of the ScanBox Framework
ScanBox is valued by threat intelligence operators because it bridges the gap between passive reconnaissance and active monitoring without the high visibility associated with deploying bespoke trojans. The framework’s initial script systematically extracts a comprehensive profile of the target machine. This includes gathering details regarding the underlying operating system, system language configurations, installed browser plugins, and legacy components such as Adobe Flash.
Furthermore, recent iterations of ScanBox incorporate advanced networking capabilities that leverage WebRTC (Web Real-Time Communication), an open-source standard supported by all major web browsers. By integrating WebRTC, the reconnaissance script can establish direct peer-to-peer communications and execute advanced network traversal techniques.
To bypass network address translators (NAT) and corporate firewalls, ScanBox utilizes Session Traversal Utilities for NAT (STUN) protocols. Working in tandem with third-party STUN servers situated across the internet, the framework can discover the mapped public IP address and port numbers allocated for User Datagram Protocol (UDP) flows on remote hosts. This implementation of Interactive Connectivity Establishment (ICE) enables the framework to communicate effectively with victim machines even when those systems are shielded behind strict enterprise firewalls or NAT gateways.
Beyond environmental profiling, ScanBox is equipped with robust keylogging functionalities. As the user navigates the compromised watering hole, every keystroke entered into web forms or input fields is silently captured and transmitted back to infrastructure controlled by TA423. This telemetry provides the adversaries with critical insight into active credentials, internal corporate communications, and navigational habits, laying the groundwork for subsequent, highly targeted intrusions.
Attribution and Historical Context of TA423 (Red Ladon)
Security researchers from Proofpoint and PwC have attributed this campaign to TA423 with moderate confidence. Historical intelligence links this group to Hainan Island, China, where analysts assess it operates under the broader umbrella of regional cyber-espionage units. Multiple independent intelligence reports from firms such as Mandiant, alongside analyses by civic investigative groups like Intrusion Truth, have historically connected the infrastructure and personnel behind TA423 to Hainan Xiandun Technology Co., a front company tied to state intelligence operations.
The group’s operational alignment with the Chinese government is well-documented. In July 2021, the United States Department of Justice (DoJ) unsealed an indictment charging four Chinese nationals linked to the Hainan Province Ministry of State Security (MSS) with global computer intrusion campaigns. The indictment explicitly stated that TA423 / Red Ladon provided long-running, dedicated support to the MSS.
The MSS functions as the primary civilian intelligence, security, and cyber police agency for the People’s Republic of China, holding responsibility for foreign intelligence, counter-intelligence, and political security. Past indictments and threat reports reveal that TA423’s mandate extends far beyond regional disputes, having historically targeted commercial secrets, intellectual property, and confidential business information across a diverse array of global industries.
Victims identified in prior investigations span the United States, Europe, the Middle East, South Africa, and various nations across the Asia-Pacific region. Targeted sectors have included aviation, defense, education, government, healthcare, biopharmaceutical research, and maritime commerce. Despite the public exposure and legal pressure resulting from the 2021 DoJ indictments, threat analysts note that TA423 has shown no discernible reduction in its operational tempo.
Chronology of Events
- July 2021: The United States Department of Justice unseals an indictment charging multiple Chinese nationals linked to the MSS and the TA423 / Red Ladon threat group for conducting global corporate espionage campaigns targeting aviation, defense, and maritime sectors.
- April 2022: TA423 initiates a concentrated cyber-espionage campaign utilizing newly registered domains, such as australianmorningnews[.]com, to distribute the ScanBox reconnaissance framework via spear-phishing lures.
- April – June 2022: The threat actor ramps up distribution of targeted messages focusing on domestic Australian organizations and offshore energy enterprises operating within the South China Sea.
- Mid-June 2022: Observations of active watering hole campaigns utilizing the ScanBox framework begin to taper off as security telemetry captures the shift in adversary infrastructure.
- Tuesday (Reporting Date): Proofpoint’s Threat Research Team and PwC’s Threat Intelligence team jointly publish a comprehensive report detailing the campaign, linking the recent ScanBox operations directly to TA423 and outlining its strategic alignment with Beijing’s regional interests.
Strategic Implications and Geopolitical Context
The timing and targeting of the 2022 ScanBox campaign offer clear insights into the evolving strategic priorities of the Chinese state apparatus. According to Sherrod DeGrippo, vice president of threat research and detection at Proofpoint, TA423’s activities directly mirror Beijing’s geopolitical objectives in maritime Southeast Asia.
"The threat actors support the Chinese government in matters related to the South China Sea, including during recent tensions in Taiwan," DeGrippo stated in an official release. "This group specifically wants to know who is active in the region and, while we can’t say for certain, their focus on naval issues is likely to remain a constant priority in places like Malaysia, Singapore, Taiwan, and Australia."
As geopolitical friction persists over territorial claims and maritime trade routes in the South China Sea, energy exploration companies and regional defense contractors remain prime targets for state-sponsored reconnaissance. The use of low-signature tools like ScanBox allows intelligence-gathering units to map human networks and technical infrastructures without tripping traditional network tripwires, providing a distinct tactical advantage in preliminary espionage phases.
Cybersecurity analysts emphasize that organizations operating within maritime, defense, and energy sectors must adapt their defensive postures to counter fileless, browser-based reconnaissance techniques. Traditional perimeter defenses and signature-based antivirus solutions are often insufficient for detecting JavaScript frameworks executed entirely within client-side browser sessions. Enterprises are advised to implement robust endpoint monitoring, restrict unauthorized script execution, and conduct rigorous awareness training to help employees identify sophisticated social engineering lures disguised as routine corporate correspondence or regional news media.







