Skip to content
← All Threat Actors
Nation-State critical China (PRC)

Weaver Ant

China-nexus (Sygnia — assessed Chinese state-sponsored based on targeting, tooling, and infrastructure) · Telecommunications infrastructure espionage / signals intelligence collection / long-duration persistent access

Reports 1
Active Since 2021
Last Reported 8 Jul 2026
Sectors Targeted communications, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • AES-encrypted China Chopper web shell variant: encrypted web shell on compromised web servers, evades signature-based detection tuned for standard China Chopper strings
  • In-memory web shell (INMemory): novel web shell executing entirely in memory without writing to disk — no on-disk artefact for file-based forensic tools to detect
  • Operational relay box (ORB) network built from compromised Zyxel and other telecoms edge devices — routes C2 and exfiltration traffic through the target telco's own infrastructure
  • Layered persistence: multiple simultaneous web shell variants across different servers, so removal of one does not terminate access
  • Re-access after remediation: persistent re-establishment following multiple defender remediation attempts across a 4-year engagement
  • Lateral movement through telecoms internal networks via web shell tunneling into administrative systems
  • Low-and-slow data collection: long-duration stealth prioritised over operational tempo, minimal noise in network logs

Known Targets

Major Asian telecommunications provider (4+ year intrusion documented by Sygnia)Telecommunications infrastructure operators across Asia (assessed broader targeting)

Analyst Notes

Exposed by Sygnia following a major incident response engagement at an Asian telecommunications provider where Weaver Ant maintained persistent access for over four years despite multiple remediation attempts. The case represents one of the most documented examples of persistent resilience in a state-backed APT intrusion: each time defenders identified and removed footholds, Weaver Ant re-established access through remaining undetected persistence mechanisms — demonstrating layered redundant implant placement as a deliberate operational strategy. The in-memory web shell (INMemory) is technically notable: executing entirely in memory leaves no filesystem artefacts for standard forensic tools, file integrity monitoring, or host-based detection to identify. The ORB network built from compromised Zyxel devices within the target telco's own infrastructure is particularly sophisticated — C2 traffic routed through the victim organisation's own edge devices is structurally indistinguishable from legitimate administrative traffic. Telecommunications operators are high-priority targets for Chinese intelligence collection: they hold call records, message metadata, and routing information for millions of users.

Also Known As

Weaver Ant (Sygnia designation)