Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SneakyChef

Also known as: adaptation, Thallium, Black Banshee, Mythic Leopard, Transparent Tribe, Agrius, OILRIG, HELIX KITTEN, Flying Kitten, Travnet, SaffronRose, Saffron Rose, AjaxSecurityTeam, Ajax Security Team, Group 26, Sayad

Description

SneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations worldwide. They have been active since at least August 2023, with a focus on leveraging old and new command and control domains. The group has been observed using lures in the form of scanned documents related to Ministries of Foreign Affairs and embassies. Talos Intelligence assesses with medium confidence that the operators are likely Chinese-speaking based on language preferences and specific targets.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Non profit
Energy
Telecommunications
Media
Education
Critical infrastructure
Healthcare
Aerospace
Manufacturing
Hospitality
Oil gas
Think tank
Food agriculture
Aviation
Gaming
Retail
Utilities
Transportation
Pharmaceutical
Mining
Information technology
Maritime
Chemical

Targeted Countries / Regions

CN
US
IN
UA
RU
KR
JP
KZ
KP
VN
SA
PL
TW
PK
MX
IL
BY
IR
GB
AE
DE
AZ
TR
NL
LB
IT
SY
FR

AI Analysis

No AI analysis yet.

ATT&CK Techniques

1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 7 Domain 13

References

  1. blog.talosintelligence.com — Cited by web research for: Thallium
  2. github.com — Cited by web research for: Agrius
  3. blog.talosintelligence.com — Cited by web research for: Gh0st
  4. firsthackersnews.com — Cited by web research for: 8a563b3091b56eb0562f5442c90b4d28d4be2946a3dc4a225b4b96134f7e447b

Intel Summary

1

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

Backdoor / C2
Government Targeting

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.