---
title: "Threat Intel Content Update: 11/12/24"
description: "Tidal Cyber's threat intelligence content updates for the week of 11/12/24. 

Threat Highlights

New Campaign object (“Pacific Rim Network Device Targeting Campaigns“) based on Sophos' recently published, wide-reaching investigation into China-based threat groups using botnets, novel vulnerability exploits, and custom malware to target firewalls and other perimeter devices.

Considering inherent challenges in securing network devices, such as telemetry collection and detection tuning, this extensive set of TTPs (45 Technique Relationships) can be useful for identifying post-exploit opportunities for detection or mitigation, allowing layering of defenses against sophisticated network device campaigns."
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 11/12/24](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-11/12/24)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Nov 12, 2024 4:00:00 PM

#### Pacific Rim Network Device Targeting Campaigns, China-based threat groups using botnets, novel vulnerability exploits, and custom malware

 

**Threat Highlights**

- **New Campaign object** (“Pacific Rim Network Device Targeting Campaigns“) based on Sophos' [recently published, wide-reaching investigation](https://news.sophos.com/en-us/2024/10/31/pacific-rim-neutralizing-china-based-threat/) into China-based threat groups using botnets, novel vulnerability exploits, and custom malware to target firewalls and other perimeter devices.
  
    - Considering inherent challenges in securing network devices, such as telemetry collection and detection tuning, this extensive set of TTPs (45 Technique Relationships) can be useful for identifying post-exploit opportunities for detection or mitigation, allowing layering of defenses against sophisticated network device campaigns.

- **Tidal Tip: **You can now review previous CTI updates on our threat content updates page [here](https://www.tidalcyber.com/threat-updates)!

**Defense Highlights**

- **Updated Vendors & Products: **Elastic Security SIEM and EDR products have been updated to version 8.15

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-11/12/24)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2024-11-21T19:25:32.890Z",
  "datePublished" : "2024-11-12T16:00:00Z",
  "headline" : "Threat Intel Content Update: 11/12/24",
  "image" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intelligence%20Content%20Update%20Social.jpg",
    "width" : 900
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-11/12/24",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```