Watering Hole Attacks Push ScanBox Keylogger

A sophisticated and persistent cyber-espionage campaign has come to light, revealing targeted digital operations directed by a China-based threat actor against critical infrastructure, domestic Australian organizations, and offshore energy firms operating in the contested South China Sea. Security researchers from Proofpoint and PwC’s Threat Intelligence team jointly uncovered a series of watering hole attacks deployed between April and June 2022. These operations were specifically designed to compromise high-profile targets by covertly delivering the ScanBox JavaScript-based reconnaissance and keylogging framework.
The threat actor orchestrating these campaigns has been identified with moderate confidence as TA423, a notorious advanced persistent threat (APT) group also widely tracked by the cybersecurity community as Red Ladon. Operating primarily out of Hainan Island, China, TA423 has a well-documented history of executing state-sponsored cyber operations aligned with the strategic geopolitical interests of the People’s Republic of China. This latest wave of attacks underscores the group’s relentless pursuit of regional intelligence, particularly concerning maritime resources, naval defense, and international commerce.
Anatomy of the Campaign: Phishing Baits and Fake News Portals
The cyber-espionage operations analyzed by Proofpoint and PwC typically began with highly targeted spear-phishing emails sent to carefully selected individuals within government, defense, and maritime energy sectors. Rather than relying on immediate file-based malware drops, which are easily flagged by modern endpoint detection and response (EDR) solutions, the threat actors employed social engineering tactics designed to lure victims toward malicious infrastructure.
The phishing communications utilized subject lines tailored to administrative and professional workflows, including phrases such as "Sick Leave," "User Research," and "Request Cooperation." To add a veneer of legitimacy, the emails purported to originate from employees of a fabricated media outlet named the "Australian Morning News." Targets were implored to visit the website australianmorningnews[.]com to review specific news items or participate in purported media collaborations.
Upon clicking the embedded hyperlinks, victims were redirected to a compromised or attacker-controlled web page that deceptively mirrored authentic, high-traffic news platforms such as the BBC and Sky News. Unbeknownst to the visitors, the infrastructure immediately loaded the ScanBox reconnaissance framework into their web browsers. By leveraging these watering hole tactics, TA423 maximized its chances of capturing credentials, keystrokes, and system telemetry from high-value individuals without alerting them to the ongoing compromise.
The Evolution and Danger of the ScanBox Framework
ScanBox is a multifunctional, modular JavaScript framework that has been utilized by various threat actors for nearly a decade. Despite its age, cybersecurity experts emphasize that ScanBox remains a potent and dangerous tool in the arsenals of state-sponsored espionage groups due to its distinct operational advantages.
Unlike traditional malware payloads that must be written to a target’s local hard drive to execute malicious functions—thereby risking detection by antivirus software—ScanBox operates entirely within the memory space of the victim’s web browser. Once injected via a compromised or cloned website, the JavaScript executes quietly, enabling continuous keylogging and environmental reconnaissance.
The framework performs comprehensive browser fingerprinting during the initial phase of infection. It rapidly harvests a wealth of telemetry regarding the host machine, including the operating system version, installed system languages, screen resolution, and legacy plugin configurations such as Adobe Flash. Furthermore, ScanBox systematically checks for browser extensions and components capable of facilitating advanced network communication, most notably WebRTC (Web Real-Time Communication).
Advanced Networking and NAT Traversal Capabilities
A particularly intricate aspect of the recent TA423 campaigns is ScanBox’s implementation of WebRTC alongside Session Traversal Utilities for NAT (STUN) servers. By integrating STUN protocols, the JavaScript framework enables attackers to bypass standard network security barriers, such as Network Address Translators (NATs) and firewalls, which typically protect corporate and governmental internal networks.
Through third-party STUN servers located on the public internet, ScanBox allows hosts to discover their mapped public IP addresses and port numbers. Utilizing Interactive Connectivity Establishment (ICE), the framework establishes direct peer-to-peer communication channels with victim machines, even when those systems are securely situated behind complex corporate firewalls. This capability ensures that the threat actors can maintain persistent, real-time connectivity and stream harvested intelligence back to their command-and-control infrastructure without raising immediate network alarms.
Chronology and Timeline of the Threat Activity
The discovery of the 2022 watering hole campaign is the culmination of extensive collaborative research into the shifting operational tactics of TA423. A review of the timeline highlights the continuous nature of the group’s intelligence-gathering missions:
- Pre-2021: TA423, operating extensively out of Hainan Island, established a long-standing pattern of targeting global industries, including aviation, defense, biopharmaceuticals, and maritime commerce, in direct support of Chinese state interests.
- July 2021: The United States Department of Justice (DoJ) unsealed a landmark indictment charging four Chinese nationals linked to the Ministry of State Security (MSS) and TA423 / Red Ladon for a decade-long global computer intrusion campaign targeting intellectual property and trade secrets across multiple continents.
- April to June 2022: TA423 launched its targeted watering hole and browser-fingerprinting campaign utilizing the ScanBox framework, focusing heavily on domestic Australian entities and offshore energy corporations operating within the South China Sea.
- June 2022: Analysts observed a tapering of this specific distribution phase as threat intelligence teams gathered telemetry to map out the infrastructure.
- July 2022: Proofpoint and PwC published formal threat analysis reports detailing the technical mechanisms of the ScanBox deployment and attributing the activity to TA423 with moderate confidence.
Attribution and State-Sponsored Nexus
Attribution of these campaigns to TA423 / Red Ladon rests on a combination of infrastructure analysis, victimology, and historical intelligence compiled by multiple cybersecurity firms and government agencies.
According to findings corroborated by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Mandiant, and private research entities, TA423 operates out of China’s Hainan Province. The group’s activities have long been assessed as providing direct operational support to the Hainan Province Ministry of State Security (MSS). The MSS functions as the primary civilian intelligence, security, and counter-intelligence agency for the People’s Republic of China, holding formal responsibility for foreign intelligence collection, political security, and the safeguarding of domestic industrial interests.
The involvement of MSS-backed actors in South China Sea operations aligns closely with Beijing’s broader geopolitical and territorial ambitions. Sherrod DeGrippo, vice president of threat research and detection at Proofpoint, noted that the threat actors actively support the Chinese government in monitoring activities within the South China Sea, particularly amid heightened regional tensions involving Taiwan, Malaysia, Singapore, and Australia. The focus on maritime and energy sectors reflects a strategic imperative to track foreign entities exploring or operating contested resource-rich zones.
Global Scope and Historical Precedent
While the 2022 campaigns highlighted specific targeting of Australian and South China Sea energy interests, TA423’s historical operational scope is truly global. The July 2021 DoJ indictment detailed a sweeping international campaign that impacted commercial and governmental entities in the United States, the United Kingdom, Canada, Australia, Germany, Norway, Switzerland, Saudi Arabia, South Africa, South Korea, Japan, and several Southeast Asian nations.
Targeted industries historically included advanced manufacturing, defense contracting, higher education, healthcare, and maritime logistics. The persistence of these campaigns indicates that public indictments and international sanctions have done little to deter the operational tempo of state-sponsored groups operating within the jurisdiction of the People’s Republic of China. Cyber threat analysts collectively anticipate that TA423 and similar red-teaming units will continue their espionage missions unabated, adapting their tooling to exploit gaps in human vigilance and browser-based security architectures.
Broader Implications and Defensive Recommendations
The deployment of framework-based reconnaissance tools like ScanBox through sophisticated watering hole attacks highlights a critical evolution in modern cyber espionage. As perimeter defenses, multi-factor authentication (MFA), and endpoint detection systems become increasingly robust across government and enterprise environments, threat actors are shifting their focus toward client-side vulnerabilities, browser environments, and trusted third-party web infrastructure.
Organizations operating in sensitive geopolitical zones, maritime energy sectors, and defense supply chains face unique challenges in mitigating these threats. Traditional antivirus solutions frequently fail to catch browser-based JavaScript execution, necessitating a multi-layered defensive posture. Cybersecurity authorities recommend that enterprises implement advanced web filtering, strict content security policies (CSPs) to block unauthorized external script execution, and continuous monitoring of outbound network connections to detect anomalies related to unauthorized STUN or ICE traffic.
Furthermore, user awareness training remains a vital line of defense against targeted spear-phishing campaigns that leverage fabricated news portals and professional pretexts. As state-sponsored actors refine their tradecraft to blend seamlessly with normal web traffic, proactive threat intelligence sharing and international cooperation between private security firms and governmental agencies remain essential in unmasking and disrupting covert cyber espionage operations before critical intelligence is compromised.





