Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SILKFIN AGENCY

Also known as: cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, 560048, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm

Description

Silkfin Agency—also catalogued under an unusually dense set of aliases including APT3, Gothic Panda, Fancy Bear, and several Iranian‑linked groups—appears to amalgamate elements from multiple well‑known APT families. Operationally, the threat actor executes a multi‑stage attack vector that begins with spear‑phishing or malvertising to drop lightweight downloaders; these drop points subsequently install a portfolio of remote access trojans such as Agent Tesla, Ghost RAT, SectopRAT and backdoor components written in native Windows binaries (e.g., Redline Stealer). Persistence mechanisms employ DLL side‑loading, process injection, and token manipulation along with service creation (T1543.003) and registry run keys (T1547.001). Subsequent exfiltration traverses a custom MQTT protocol over non‑standard ports—most notably 52997—and tunnels through HTTPS or DNS to avoid detection. In addition to espionage, Silkfin leverages a double‑extortion ransomware variant called AttackNew, a derivative of MedusaLocker that encrypts victim files with RSA/AES and appends a unique ".attacknew1" extension. The actor follows up with blackmail pressure, threatening to release captured data. Recent incidents demonstrate the group's capacity for high‑value compromise: August 2024 saw infiltration of Indonesia’s Ministry of Transportation; historical operations include breaches of DimeCuba.com, Sri Lanka’s Department of Agrarian Development and Siam Cement Group.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Aerospace
Media
Information technology
Education
Healthcare
Manufacturing
Pharmaceutical
Maritime
Think tank
Transportation
Chemical
Retail
Entertainment
Hospitality
Mining
Nuclear
Gaming
Legal services
Critical infrastructure
Utilities
Construction
Food agriculture

Targeted Countries / Regions

US
CN
GB
IN
KR
JP
DE
RU
SA
IR
FR
CA
TW
IL
TR
AU
PK
KZ
ES
IT
PL
UA
VN
BR
SG
NL
BY
RO
AE
IQ
MX
SY
AZ
KP
EG
LB

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

Silkfin Agency is a highly sophisticated cyber‑espionage actor that conducts long‑term, stealthy operations targeting government, defense, energy, finance, healthcare and other critical sectors worldwide. Its malware pipeline delivers lightweight downloaders via phishing or malvertising, installs remote access trojans and custom backdoors, and exfiltrates data using a proprietary MQTT‑based C2 channel. The group also monetizes its operations through double‐extortion ransomware (AttackNew), threatening to publish compromised data if ransom demands are not met.

Goals & Targeting

Silkfin’s strategic objectives blend traditional state‑supported espionage with opportunistic financial exploitation. By infiltrating governments (US, UK, JP), defense contractors, critical infrastructure providers (energy, aerospace, nuclear) and high‑profile commercial entities, the actor seeks to harvest politically or economically sensitive intelligence that can influence diplomatic decisions or provide leverage in trade negotiations. The double‑extortion ransomware component indicates an intent to profit from acquired data if disclosure is deemed valuable. Typical victims are mid‑to‑large organizations with robust internal security but exposed supply chains—government ministries, defense contractors, banking institutions and multinational enterprises—particularly those in geopolitically strategic regions such as the Indo‑Pacific, Middle East and Eastern Europe.

Enhanced Description

Key Capabilities

  • spear‑phishing and malvertising delivery
  • lightweight downloader deployment
  • remote access trojan installation (Agent Tesla, Ghost RAT, SectopRAT)
  • custom native backdoor with MQTT C2 on non‑standard ports
  • DLL side‑loading and process injection for stealth
  • token manipulation and privilege escalation
  • persistence via Windows services and registry run keys
  • data staging and exfiltration over HTTPS/DNS tunnels
  • double‑extortion ransomware execution (AttackNew)
  • defense evasion through obfuscation, virtualization detection, and indicator removal

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Acquisition
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control
Defense Evasion
Impact

ATT&CK Techniques

T1059.001
T1056.001
T1003
T1071
T1041
T1018
T1082
T1140
T1064
T1055
T1543.003
T1547.001
T1083
T1074
T1489
T1129
T1134
T1497
T1518.001
T1046
T1021.001
T1057
T1562.001

Software / Tooling

Agent Tesla
Ghost RAT
SectopRAT
Redline Stealer
AttackNew (MedusaLocker variant)
Custom MQTT‑based backdoor
PowerShell scripts

Campaigns & Victims

Silkfin’s campaigns are executed with a blend of rapid, broad‑spray tactics followed by long‑term, in‑depth operations. The actor employs large‑scale spear‑phishing or watering‑hole attacks to gain initial footholds, then quickly expands its reach through lateral movement within the victim environment. Incidents span multiple continents from Asia to Europe and involve both public sector ministries and private industrial corporations such as Siam Cement Group. Operational tempo appears high: significant breaches are reported every few months (e.g., August 2024 Indonesian Ministry attack) while maintaining persistence for extended periods to allow comprehensive data collection. The actor’s recent focus on high‑visibility governmental entities aligns with a pattern of extracting actionable intelligence that can be leveraged for political or economic advantage, while the introduction of double‑extortion ransomware demonstrates a shift toward monetization where applicable.

IOC Patterns

  • Spear‑phishing with lightweight downloaders
  • DLL side‑loading and process injection into legitimate processes
  • MQTT‑based command & control over non‑standard ports (e.g., 52997)
  • Custom double‑extortion ransomware with ".attacknew1" extension
  • Exfiltration via HTTPS/TLS or DNS tunneling

Recommended Actions

  • Deploy multi‑factor authentication on all privileged accounts and critical services.
  • Implement endpoint detection and response tools that flag use of obscure PowerShell modules, keylogging, and process injection.
  • Segment networks to contain lateral movement; conduct regular network segmentation reviews. Enforce strict outbound traffic controls for MQTT and unusual DNS queries. Use threat intelligence feeds to block known malicious domains and IPs associated with Silkfin; Monitor file system for unexpected creation of the ".attacknew1" extension and sudden AES/RSA encryption patterns. Conduct user‑education campaigns focusing on phishing recognition and safe attachment handling.

Confidence Assessment

The intelligence reflects a highly contested attribution environment. Many of Silkfin’s aliases correspond to distinct, well‑documented APT families (e.g., Fancy Bear/APT28, Charming Kitten/Parastoo), indicating potential conflation in the public data set. Assertions about specific malware pipelines and double‑extortion ransomware are based on August 2024 reports; earlier references to older campaigns lack recent corroboration. Consequently, confidence is moderate for operational patterns (phishing, downloader deployment, RAT usage) but lower for claims of cross‑group alias overlap and the precise capabilities of the custom MQTT backdoor. Key information gaps include detailed attribution evidence linking the actor’s numerous aliases, up‑to‑date indicators of compromise beyond dated domain samples, and long‑term persistence artifacts in target environments.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

Intel Summary

37

Techniques

52

Tools

0

Campaigns

39

IOCs

0

Observed Data

12

Tactics

Tags

Data Exfiltration
Financial Espionage
Data Breach
Nation-State Activity
Emerging Markets Targeting
State‑sponsored
Espionage
RAT
Keylogging
Credential Dumping
Malvertising
Persistence‐via‐Services
Registry‑based Persistence
DLL Side‑Loading
Process Injection
Token Manipulation
Data Exfiltration
Application‑Layer C2
MQTT C2
Double Extortion
Ransomware
MedusaLocker Variant
AttackNew
Android Malware
HTTPS TLS Intercept
Virtualization Evasion
Defense Evasion
Privilege Escalation

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.