In September 2024 Sophos X-Ops published further findings on Operation Crimson Palace, a campaign it describes as running for nearly two years against a high-profile government organisation in Southeast Asia. It identifies three separate clusters of Chinese state-sponsored activity inside that organisation, designated Alpha, Bravo and Charlie.
After a reported hiatus around August 2023, Bravo and Charlie activity resumed. Bravo is described as reappearing in January 2024 and targeting at least eleven further organisations and agencies in the region. The assessed objective is long-term espionage, with the clusters maintaining redundant command-and-control channels. A keylogger described as novel, named Tattletale, is reported as capable of impersonating signed-in users and gathering password policy information.
Three Operators, One Victim, No Collision
We filed one actor per intrusion almost without exception. Where it has recorded more than one, at 23-0715, two ransomware operations arrived at the same company by unrelated routes and neither knew about the other.
This is a different arrangement. Three clusters attributed to one state’s apparatus, in one organisation, building parallel access rather than contesting it. That is not a coincidence of targeting; it reads as separate teams tasked against the same objective, and it implies a coordinating layer this desk cannot see and does not claim to.
Redundancy Is The Tell
Criminal intrusion optimises for speed to payment. Redundant command channels across a network cost effort and add exposure, and buy only one thing: surviving eviction.
We have argued at 23-0724 and 26-0703 that long-dwell state activity is distinguishable from criminal activity by what it invests in rather than by what it takes. Three clusters maintaining independent channels is the clearest expression of that in this database — an operation planning to be there after being found.
The Victim Has No Name In This File
The affected organisation is described only as a high-profile government body in Southeast Asia. The eleven further organisations are not identified either.
That is normal for espionage reporting and it is a real limit. We have recorded at 23-0919 that espionage succeeds by producing no artefact, and this file is the adjacent problem: an artefact exists, and it has been anonymised to the point where no affected population can be identified, no regulator is engaged, and nobody can be told. The desk carries the research and states plainly that it cannot verify who this happened to.
Compiled from Sophos X-Ops’ published Crimson Palace research and contemporaneous reporting of it, listed below. The victim organisation is unnamed in the source and is unnamed here; this desk has not independently verified any element of the account, which with the single-source basis is why the file is graded medium. The characterisation of the activity as Chinese state-sponsored is the vendor’s assessment and is carried as such; this desk attributes nothing to any state. No indicators are reproduced. Corrections: corrections@forensicpost.com.