Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Anonymous64

Also known as: Anonymous 64, Neon Pothos, Ursa, Poison Vine, Green Spot, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, APT-C-01

Description

Anonymous64—also referred to in some reports as Anonymous 64, Neon Pothos or Ursa—has emerged primarily from allegations by Chinese authorities that the group is linked to a Taiwanese defense unit consisting of active‑duty military personnel. According to the Ministry of State Security, Anonymous64 has attempted to seize control of web portals, outdoor electronic displays and broadcast television networks in order to sabotage communications and influence public sentiment. The narrative portrays Anonymous64 as an “influence operation” disguised under the form of hacktivism and is said to employ sabotage tactics against China’s domestic media landscape. From the limited publicly available data, Anonymous64 appears to combine classic threat actor techniques such as exploitation of external remote services (e.g., T1190, T1133), exfiltration over web services and alternative protocols (T1567, T1048) with ransomware‑like impact actions (T1486, T1657). It also reportedly uses a variety of third‑party tools—Machete, BlackCat/BlackSuit, Carbanak, Royal/Void, and others—suggesting either sophisticated threat‑sharing or modular malware supply chains. The group’s stated primary motive is financial gain, but the emphasis on sabotaging public media indicates a dual agenda blending economic theft with political influence. Their broad sector coverage—from government and defense to telecommunications, energy, healthcare, education, finance, and critical infrastructure—aligns with an operation that aims both at monetization through data exfiltration or ransomware and at achieving public‑fear outcomes by crippling essential services. Despite the lack of confirmed independent incident reports, repeated associations with high‑profile tool families and a consistent alignment with Chinese‑linked actors give Anonymous64 credibility as a threat capable of global reach and multi‑domain disruption.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Education
Healthcare
Manufacturing
Media
Non profit
Critical infrastructure
Energy
Hospitality
Retail
Pharmaceutical
Aviation
Aerospace
Information technology
Transportation
Think tank
Gaming
Mining
Chemical
Legal services
Nuclear
Entertainment
Maritime
Construction
Oil gas
Utilities
Food agriculture

Targeted Countries / Regions

CN
US
TW
RU
JP
IR
GB
UA
AE
VN
AU
IN
PK
IL
SA
DE
BY
SG
KR
KP
PL
CA
TR
MX
ES
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· 6 hours ago

Executive Summary

Anonymous64 is alleged by China’s Ministry of State Security to be a state-linked sabotage/cyber‑harassment group reportedly controlled by a unit in Taiwan’s defense ministry. The actor has been accused of targeting public‑facing web portals, outdoor electronic billboards and network television stations to disrupt services and influence public opinion, while also pursuing financial theft. Its operational footprint spans the United States, China, Ukraine, Europe, Southeast Asia and the Middle East across a wide array of critical infrastructure sectors.

Goals & Targeting

Anonymous64’s strategic objectives blend financial theft with sabotage of public communications. By targeting web portals, outdoor billboards and network TV stations it seeks to undermine trust in media infrastructures and generate widespread alarm—an outcome consistent with influence operations. At the same time, its use of ransomware families (e.g., BlackCat) implies a secondary objective of extortion or theft of payments from victims worldwide. Typical victims are government agencies responsible for public information, media outlets that distribute news to large audiences, as well as organizations within critical infrastructure whose disruption can cause cascading economic and societal effects. The group’s geographic focus on the United States, China, Europe, Middle East and Asia‑Pacific reflects both its alleged ties to Taiwan/China state actors and a desire to pressure adversarial governments while exploiting financial opportunities in diverse markets. The sheer breadth of targeted sectors—spanning defense, energy, healthcare, finance, telecommunications, education and manufacturing—demonstrates an intent to expose wide institutional vulnerabilities and capitalize on the global reach of the modern cyber‑economy.

Enhanced Description

Key Capabilities

  • Exploitation of public-facing web services for initial access
  • Use of external remote services (T1133) for lateral movement
  • Execution via custom backdoors and RATs (e.g., Machete, BlackCat, Carbanak)
  • Data exfiltration over web services and alternative protocols
  • Deployment of ransomware and data‑encryption for impact (T1486)
  • Spear‑phishing or broad phishing campaigns to distribute weaponized attachments
  • Potential sabotage/defacement of public media infrastructure
  • Ability to coordinate multi‑sector attacks across different industries

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Exfiltration
Command and Control
Impact

ATT&CK Techniques

T1190
T1133
T1567
T1048
T1657
T1486
T1059.001
T1071.001
T1204.002
T1505.003
T1105
T1064

Software / Tooling

Machete
BlackCat
BlackSuit
Carbanak
Royal
AppleJeus
Mythic
PitTTyTiger
Cobalt Strike
Phishing campaigns
Winnti

Campaigns & Victims

Anonymous64 is linked to a variety of open‑source intelligence reports that map it onto broader state‑aligned threat families such as Deep Panda and Shell Crew. While no confirmed, publicly documented campaign solely attributed to Anonymous64 exists, the pattern suggests opportunistic use of external-remote-service exploitation against publicly accessible web infrastructure coupled with ransomware or sabotage payloads. The operational tempo appears irregular—attacks are reported sporadically but involve high‑impact targets. Victims tend to be medium to large organizations in sectors where a sudden outage can inflict significant reputational damage, and the group’s toolset indicates both rapid deployment of ready‑made malware and bespoke scripts for target‑specific sabotage. Notable past operations associated with related groups include the 2015–17 attacks against Ukrainian electric grids (Sandworm), NotPetya ransomware (also tied to Sandworm/Group 74455), and the Deep Panda intrusion into Anthem, a major U.S. health insurer. These incidents collectively demonstrate the group’s capacity for wide‑scale disruption, financial theft, and political influence. Given overlaps in tool use and attribution frameworks, Anonymous64 likely operates within an ecosystem of overlapping threat actors that share information, infrastructure and tactics to carry out financially motivated sabotage on a global stage.

IOC Patterns

  • Spear‑phishing via email addresses with uncommon domain patterns (e.g., rocke@live.cn)
  • Use of temporary or “TEMP.” prefixed domains for command‑and‑control traffic (e.g., TEMP.Zagros, TEMP.Akapav)
  • Deployment of unknown/ custom backdoors disguised under legitimate service names
  • Exfiltration via common web services such as demo-cloud.space
  • Phishing campaigns leveraging macro‑laden Office documents
  • Use of public-facing web portals and TV broadcast infrastructure as attack vectors

Recommended Actions

  • Secure all public‑facing web applications with strict patching cycles and implement Web Application Firewalls (WAFs); Conduct regular vulnerability scanning for external remote services and ensure zero‑trust network segmentation; Deploy multi‑factor authentication on admin panels of web portals, television broadcast control systems, and electronic billboard controls; Implement endpoint detection & response solutions capable of detecting ransomware execution and unusual encryption activity; Block known malicious domains (e.g., demo-cloud.space, TEMP.* domains) via DNS filtering or UTM appliances; Conduct user awareness training focused on spear‑phishing, macro‑linked documents and suspicious email attachments; Establish incident response playbooks that include sabotage scenarios for critical communication infrastructure; Maintain up‑to‑date backups of public content and media control configurations to quickly restore after defacement.

Suggested Tags

APT
State‑Sponsored
Hacktivism
Sabotage
Illicit Financial Theft
Critical Infrastructure Attack
Media Disruption
Ransomware
Chinese‑Linked

Confidence Assessment

The intelligence about Anonymous64 relies chiefly on allegations from China’s Ministry of State Security and secondary attribution to a Taiwanese defense unit, with no independently confirmed incident reports publicly available. The presence of linked MITRE techniques and a wide array of known tool families suggests the group operates with moderate sophistication, but the exact operational footprint remains uncertain. There is a notable lack of verifiable attack narratives or threat‑actor artifacts directly tied to Anonymous64 alone; many references are conflated with other similarly named groups (e.g., Deep Panda). Consequently, confidence in details about specific campaigns, victim profiles and precise motivations is moderate at best, and further evidence such as malware samples, incident logs or corroborating attribution would be needed to increase certainty.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. unit42.paloaltonetworks.com — Cited by web research for: Royal Ransomware
  3. www.nattothoughts.com — Cited by web research for: APT-C-01
  4. www.giovannicarrieri.it — Cited by web research for: theregister.com
  5. https://www.cisa.gov — Cited by AI analysis.
  6. https://www.fireeye.com — Cited by AI analysis.
  7. https://www.mandiant.com — Cited by AI analysis.

Intel Summary

12

Techniques

42

Tools

0

Campaigns

15

IOCs

0

Observed Data

7

Tactics

Tags

Government Targeting
Hacktivism
APT
State-sponsored
Influence operations
媒体行业
网络战
Critical Infrastructure
State‑Sponsored
Sabotage
Illicit Financial Theft
Critical Infrastructure Attack
Media Disruption
Ransomware
Chinese‑Linked

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
T
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.