Also known as: cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, 560048, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm
Silkfin Agency—also catalogued under an unusually dense set of aliases including APT3, Gothic Panda, Fancy Bear, and several Iranian‑linked groups—appears to amalgamate elements from multiple well‑known APT families. Operationally, the threat actor executes a multi‑stage attack vector that begins with spear‑phishing or malvertising to drop lightweight downloaders; these drop points subsequently install a portfolio of remote access trojans such as Agent Tesla, Ghost RAT, SectopRAT and backdoor components written in native Windows binaries (e.g., Redline Stealer). Persistence mechanisms employ DLL side‑loading, process injection, and token manipulation along with service creation (T1543.003) and registry run keys (T1547.001). Subsequent exfiltration traverses a custom MQTT protocol over non‑standard ports—most notably 52997—and tunnels through HTTPS or DNS to avoid detection. In addition to espionage, Silkfin leverages a double‑extortion ransomware variant called AttackNew, a derivative of MedusaLocker that encrypts victim files with RSA/AES and appends a unique ".attacknew1" extension. The actor follows up with blackmail pressure, threatening to release captured data. Recent incidents demonstrate the group's capacity for high‑value compromise: August 2024 saw infiltration of Indonesia’s Ministry of Transportation; historical operations include breaches of DimeCuba.com, Sri Lanka’s Department of Agrarian Development and Siam Cement Group.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Silkfin Agency is a highly sophisticated cyber‑espionage actor that conducts long‑term, stealthy operations targeting government, defense, energy, finance, healthcare and other critical sectors worldwide. Its malware pipeline delivers lightweight downloaders via phishing or malvertising, installs remote access trojans and custom backdoors, and exfiltrates data using a proprietary MQTT‑based C2 channel. The group also monetizes its operations through double‐extortion ransomware (AttackNew), threatening to publish compromised data if ransom demands are not met.
Goals & Targeting
Silkfin’s strategic objectives blend traditional state‑supported espionage with opportunistic financial exploitation. By infiltrating governments (US, UK, JP), defense contractors, critical infrastructure providers (energy, aerospace, nuclear) and high‑profile commercial entities, the actor seeks to harvest politically or economically sensitive intelligence that can influence diplomatic decisions or provide leverage in trade negotiations. The double‑extortion ransomware component indicates an intent to profit from acquired data if disclosure is deemed valuable. Typical victims are mid‑to‑large organizations with robust internal security but exposed supply chains—government ministries, defense contractors, banking institutions and multinational enterprises—particularly those in geopolitically strategic regions such as the Indo‑Pacific, Middle East and Eastern Europe.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Silkfin’s campaigns are executed with a blend of rapid, broad‑spray tactics followed by long‑term, in‑depth operations. The actor employs large‑scale spear‑phishing or watering‑hole attacks to gain initial footholds, then quickly expands its reach through lateral movement within the victim environment. Incidents span multiple continents from Asia to Europe and involve both public sector ministries and private industrial corporations such as Siam Cement Group. Operational tempo appears high: significant breaches are reported every few months (e.g., August 2024 Indonesian Ministry attack) while maintaining persistence for extended periods to allow comprehensive data collection. The actor’s recent focus on high‑visibility governmental entities aligns with a pattern of extracting actionable intelligence that can be leveraged for political or economic advantage, while the introduction of double‑extortion ransomware demonstrates a shift toward monetization where applicable.
IOC Patterns
Recommended Actions
Confidence Assessment
The intelligence reflects a highly contested attribution environment. Many of Silkfin’s aliases correspond to distinct, well‑documented APT families (e.g., Fancy Bear/APT28, Charming Kitten/Parastoo), indicating potential conflation in the public data set. Assertions about specific malware pipelines and double‑extortion ransomware are based on August 2024 reports; earlier references to older campaigns lack recent corroboration. Consequently, confidence is moderate for operational patterns (phishing, downloader deployment, RAT usage) but lower for claims of cross‑group alias overlap and the precise capabilities of the custom MQTT backdoor. Key information gaps include detailed attribution evidence linking the actor’s numerous aliases, up‑to‑date indicators of compromise beyond dated domain samples, and long‑term persistence artifacts in target environments.
No campaigns linked yet.
No observed data linked yet.
37
Techniques
52
Tools
0
Campaigns
39
IOCs
0
Observed Data
12
Tactics