Also known as: adaptation, Thallium, Black Banshee, Mythic Leopard, Transparent Tribe, Agrius, OILRIG, HELIX KITTEN, Flying Kitten, Travnet, SaffronRose, Saffron Rose, AjaxSecurityTeam, Ajax Security Team, Group 26, Sayad
SneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations worldwide. They have been active since at least August 2023, with a focus on leveraging old and new command and control domains. The group has been observed using lures in the form of scanned documents related to Ministries of Foreign Affairs and embassies. Talos Intelligence assesses with medium confidence that the operators are likely Chinese-speaking based on language preferences and specific targets.
Targeted Sectors
Targeted Countries / Regions
No AI analysis yet.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
1
Tactics