Also known as: Anonymous 64, Neon Pothos, Ursa, Poison Vine, Green Spot, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, APT-C-01
Anonymous64—also referred to in some reports as Anonymous 64, Neon Pothos or Ursa—has emerged primarily from allegations by Chinese authorities that the group is linked to a Taiwanese defense unit consisting of active‑duty military personnel. According to the Ministry of State Security, Anonymous64 has attempted to seize control of web portals, outdoor electronic displays and broadcast television networks in order to sabotage communications and influence public sentiment. The narrative portrays Anonymous64 as an “influence operation” disguised under the form of hacktivism and is said to employ sabotage tactics against China’s domestic media landscape. From the limited publicly available data, Anonymous64 appears to combine classic threat actor techniques such as exploitation of external remote services (e.g., T1190, T1133), exfiltration over web services and alternative protocols (T1567, T1048) with ransomware‑like impact actions (T1486, T1657). It also reportedly uses a variety of third‑party tools—Machete, BlackCat/BlackSuit, Carbanak, Royal/Void, and others—suggesting either sophisticated threat‑sharing or modular malware supply chains. The group’s stated primary motive is financial gain, but the emphasis on sabotaging public media indicates a dual agenda blending economic theft with political influence. Their broad sector coverage—from government and defense to telecommunications, energy, healthcare, education, finance, and critical infrastructure—aligns with an operation that aims both at monetization through data exfiltration or ransomware and at achieving public‑fear outcomes by crippling essential services. Despite the lack of confirmed independent incident reports, repeated associations with high‑profile tool families and a consistent alignment with Chinese‑linked actors give Anonymous64 credibility as a threat capable of global reach and multi‑domain disruption.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Anonymous64 is alleged by China’s Ministry of State Security to be a state-linked sabotage/cyber‑harassment group reportedly controlled by a unit in Taiwan’s defense ministry. The actor has been accused of targeting public‑facing web portals, outdoor electronic billboards and network television stations to disrupt services and influence public opinion, while also pursuing financial theft. Its operational footprint spans the United States, China, Ukraine, Europe, Southeast Asia and the Middle East across a wide array of critical infrastructure sectors.
Goals & Targeting
Anonymous64’s strategic objectives blend financial theft with sabotage of public communications. By targeting web portals, outdoor billboards and network TV stations it seeks to undermine trust in media infrastructures and generate widespread alarm—an outcome consistent with influence operations. At the same time, its use of ransomware families (e.g., BlackCat) implies a secondary objective of extortion or theft of payments from victims worldwide. Typical victims are government agencies responsible for public information, media outlets that distribute news to large audiences, as well as organizations within critical infrastructure whose disruption can cause cascading economic and societal effects. The group’s geographic focus on the United States, China, Europe, Middle East and Asia‑Pacific reflects both its alleged ties to Taiwan/China state actors and a desire to pressure adversarial governments while exploiting financial opportunities in diverse markets. The sheer breadth of targeted sectors—spanning defense, energy, healthcare, finance, telecommunications, education and manufacturing—demonstrates an intent to expose wide institutional vulnerabilities and capitalize on the global reach of the modern cyber‑economy.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Anonymous64 is linked to a variety of open‑source intelligence reports that map it onto broader state‑aligned threat families such as Deep Panda and Shell Crew. While no confirmed, publicly documented campaign solely attributed to Anonymous64 exists, the pattern suggests opportunistic use of external-remote-service exploitation against publicly accessible web infrastructure coupled with ransomware or sabotage payloads. The operational tempo appears irregular—attacks are reported sporadically but involve high‑impact targets. Victims tend to be medium to large organizations in sectors where a sudden outage can inflict significant reputational damage, and the group’s toolset indicates both rapid deployment of ready‑made malware and bespoke scripts for target‑specific sabotage. Notable past operations associated with related groups include the 2015–17 attacks against Ukrainian electric grids (Sandworm), NotPetya ransomware (also tied to Sandworm/Group 74455), and the Deep Panda intrusion into Anthem, a major U.S. health insurer. These incidents collectively demonstrate the group’s capacity for wide‑scale disruption, financial theft, and political influence. Given overlaps in tool use and attribution frameworks, Anonymous64 likely operates within an ecosystem of overlapping threat actors that share information, infrastructure and tactics to carry out financially motivated sabotage on a global stage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence about Anonymous64 relies chiefly on allegations from China’s Ministry of State Security and secondary attribution to a Taiwanese defense unit, with no independently confirmed incident reports publicly available. The presence of linked MITRE techniques and a wide array of known tool families suggests the group operates with moderate sophistication, but the exact operational footprint remains uncertain. There is a notable lack of verifiable attack narratives or threat‑actor artifacts directly tied to Anonymous64 alone; many references are conflated with other similarly named groups (e.g., Deep Panda). Consequently, confidence in details about specific campaigns, victim profiles and precise motivations is moderate at best, and further evidence such as malware samples, incident logs or corroborating attribution would be needed to increase certainty.
No campaigns linked yet.
No observed data linked yet.
12
Techniques
42
Tools
0
Campaigns
15
IOCs
0
Observed Data
7
Tactics