Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Teleboyi

Also known as: DeputyDog, tracked as, APT37, Ricochet Chollima, ScarCruft, Reaper Group, Spring Dragon, Billbug, manufacturing, telecom, Vietnam, Hong Kong, Rare Wolf, Belarusian, Ukrainian industrial enterprises, Gamaredon, verifying the signature, Shadows, Comet, Darkstar, to carry out attacks, APT44, BlackEnergy, PHANTOM, UAC-0133, Blue Echidna, Sandworm, UNK_CraftyCamel, ZDI-25-148, Thrip

Description

Teleboyi, also referred to in open-source intelligence as DeputyDog or APT37 in some reports, emerged as a highly adaptable threat actor that has consistently exploited both software vulnerabilities and social engineering tactics. The group’s hallmark signature is the use of PlugX RAT modules delivered via custom C# loaders that modify registry entries to disable autoruns, drop secondary payloads, and evade Windows Mark‑of‑the Web protection through double‑archiving techniques. Operationally, Teleboyi combines automated exploitation pipelines with targeted phishing emails aimed at Chinese‑speaking professional audiences across industries in Asia‑Pacific. These campaigns employ malicious LNK file attachments containing hidden command‑line arguments to trigger short‑lived PowerShell scripts (VeilShell Trojan) and DLL execution, followed by the installation of a download‑and‑run component that fetches additional binaries over HTTP/2 or QUIC. The actor also registers domain names mimicking legitimate targets, thereby facilitating credential harvesting via web shells. Once compromised, Teleboyi often injects malicious code into svchost.exe to maintain persistence and exfiltrate data using custom Go‑written modules that perform HTTP GET/POST requests to back‑end C&C servers. Their toolkit includes a broad spectrum of commercial exploitation frameworks such as Impacket, Mythic, and quasarRAT, alongside bespoke loaders like GuLoader and Lumma Stealer. In recent campaigns, the group demonstrated an advanced capability to manipulate Windows shortcut (.lnk) files to bypass local application controls and execute stealthy payloads. These tactics have allowed Teleboyi to infiltrate key sectors, including energy, defense, and telecommunications, often exploiting widely publicized CVEs such as CVE‑2024‑1709, CVE‑2023‑48788 and CVE‑2021‑34473. Overall, Teleboyi operates with a clear commercial agenda while simultaneously leveraging the strategic advantages of zero‑day exploits to maintain an evolving threat posture across multiple continents.

Goals & Targeting

Targeted Sectors

Government
Financial services
Manufacturing
Telecommunications
Education
Energy
Defense
Transportation
Critical infrastructure
Pharmaceutical
Maritime
Media
Oil gas
Healthcare
Construction
Retail
Nuclear
Mining
Entertainment
Chemical
Utilities
Aerospace
Aviation
Legal services

Targeted Countries / Regions

CN
JP
US
TW
RU
UA
VN
AE
KR
SG
BR
GB
IL
IR
AU
IN

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Teleboyi is a financially motivated threat actor, presumed headquartered in China, that employs PlugX-based RATs and custom obfuscated loaders to infiltrate high‑value targets across multiple sectors worldwide. The group leverages zero‑day vulnerabilities (e.g., 7‑Zip CVE‑2025‑0411) alongside phishing campaigns targeting Chinese-speaking users, using malicious LNK files, DLL injections, and domain spoofing to gain initial access and establish persistence. Their operations span government, financial services, telecommunications, manufacturing and critical infrastructure across continents, evidencing a broad geographic reach and well‑organized campaign structure.

Goals & Targeting

Teleboyi’s strategic objective is primarily financial gain, achieved by targeting sectors that retain large amounts of intellectual and proprietary data. The actor focuses on high‑profile industries—government agencies, manufacturing firms, telecommunications providers, energy utilities and critical infrastructure—to maximize the value of stolen credentials, trade secrets and financial information. The group deliberately expands its reach across both geopolitical regions (e.g., North America, Europe, East Asia) and industry verticals, indicating a pursuit of diverse revenue streams. By exploiting known CVEs in public‑facing software—such as Microsoft applications, internet servers, and network appliances—Teleboyi lowers the barrier to entry while simultaneously leveraging phishing campaigns tailored to local languages, improving the likelihood of successful credential compromise. In addition to direct monetary theft, Teleboyi’s use of plug‑in RATs and data exfiltration modules suggests secondary objectives such as strategic information gathering to facilitate future attacks or blackmail. The actor’s ability to obscure execution through DLL injection and shortcut exploitation enables long‑term persistence, thereby enabling recurring revenue opportunities. Keycapabilities: - Phishing campaigns targeting Chinese‑speaking users across Asia‑Pacific industries - Exploitation of zero‑day vulnerabilities such as CVE‑2025‑0411 (7‑Zip) and other public software flaws for initial access - Use of obfuscated C# loaders that modify registry keys to disable autoruns and drop second‑stage payloads - Execution via LNK file attachments, DLL execution, PowerShell scripts, and web shells - Deployment of additional malicious binaries over HTTP/2, QUIC, and standard HTTP protocols - Exfiltration of system data using GET and POST over multiple HTTP versions (1.1 – 3.0) - Evasion of Windows Mark‑of‑the Web protection through double archiving techniques - Initial access via exploitation of public-facing software vulnerabilities - DLL injection into svchost.exe to load malicious modules and gain persistence - Crafting of .lnk files with hidden command‑line arguments for covert execution - Domain spoofing by registering domain names that mimic victim domains

Enhanced Description

Key Capabilities

  • Phishing campaigns targeting Chinese‑speaking users across Asia‑Pacific industries
  • Exploitation of zero‑day vulnerabilities such as CVE‑2025‑0411 (7‑Zip) and other public software flaws for initial access
  • Use of obfuscated C# loaders that modify registry keys to disable autoruns and drop second‑stage payloads
  • Execution via LNK file attachments, DLL execution, PowerShell scripts (VeilShell Trojan), and web shells
  • Deployment of additional malicious binaries over HTTP/2, QUIC, and standard HTTP protocols
  • Exfiltration of system data using GET and POST over multiple HTTP versions (1.1 – 3.0)
  • Evasion of Windows Mark‑of‑the Web protection through double archiving techniques
  • Initial access via exploitation of public-facing software vulnerabilities
  • DLL injection into svchost.exe to load malicious modules and gain persistence
  • Crafting of .lnk files with hidden command‑line arguments for covert execution
  • Domain spoofing by registering domain names that mimic victim domains

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1190
T1220
T1055

Software / Tooling

PlugX RAT
Sagerunex
ShadowPad
Impacket
Mythic
QuasarRAT
Cobalt Strike
Winnti malware
J‑magic
MintsLoader
Lumma Stealer
GuLoader
Remcos
exfiltration.dll
PowerShell scripts
Malicious LNK files

Campaigns & Victims

Teleboyi has conducted a series of coordinated campaigns—most recently dubbed the BadPilot operation—across multiple nationalities, exploiting high‑profile CVEs such as CVE‑2024‑1709, CVE‑2023‑48788 and CVE‑2021‑34473 to compromise public‑facing applications. The group frequently uses a zero‑day in the widely deployed 7‑Zip utility (CVE‑2025‑0411) to bypass initial defenses. Typical attack vectors involve either phishing emails bearing malicious LNK attachments or direct exploitation of remotely exposed software via known vulnerabilities. Once foothold is achieved, Teleboyi deploys a custom C# loader that modifies registry keys, disables autoruns and drops secondary stages (including PlugX RAT modules), followed by DLL injection into svchost.exe for persistence. The actor’s use of domain spoofing—registering innocuous domains such as updata.dsqurey.com that replicate legitimate vendor names—highlights an emphasis on supply‑chain or credential‑phishing attacks, often integrated with web shell deployments. Teleboyi operates with a high operational tempo, moving quickly from initial compromise to exfiltration and persistence, while maintaining a broad geographic footprint covering the US, UK, EU, Russia, Ukraine, Vietnam, China, Japan and several other nations. Victims have primarily been in government agencies, financial services, telecommunications, energy utilities and manufacturing sectors—demonstrating a clear pattern of targeting high‑value targets that are likely to yield significant illicit returns. ioc_patterns:

IOC Patterns

  • CVE identifiers (e.g., CVE-2025-0411, CVE-2024-1709, CVE-2023-48788)
  • Suspicious DLL name exfiltration.dll
  • Go-based custom exfiltration module
  • Domain names mimicking legitimate targets (demo-cloud.space, attack.mitre.org, cisa.gov, updata.dsqurey.com, BI.ZONE, note.youdao.com, myqcloud.com, crostech.ru, thelightpower.info, mail.gkrzn.ru)
  • Malicious Windows shortcut (.lnk) files containing hidden command-line arguments
  • File names: cmd.exe, mshta.exe, CQHashDumpv2.exe, LOC.dll, usysdiag.exe, mspaint.exe, form.rar, list.docx, filling.pdf.exe, RegAsm.exe

Recommended Actions

  • Patch all software vulnerabilities immediately, prioritizing CVE-2025-0411 (7-Zip), CVE-2024-1709, CVE-2023-48788, CVE-2021-34473; implement continuous patch management.
  • Deploy endpoint detection and response tools capable of detecting DLL injection into svchost.exe and malicious execution via LNK files; configure file integrity monitoring on critical system binaries.
  • Enforce strict mail filtering rules to block phishing attempts that use LNK attachments, including sandboxing or automated quarantine.
  • Implement domain-based threat intelligence feeds (e.g., list of spoofed domains) and DNS sinkholes to pre‑empt domain spoofing infiltration.
  • Deploy anomaly‑based monitoring for Go-written exfiltration modules that communicate over HTTP/1.x through 3.x; log all outbound POST/GET requests with unusual size or frequency patterns.
  • Segment network zones, enforce the principle of least privilege, restrict external remote services and apply zero trust principles to application access.
  • Maintain up‑to‑date signatures for PlugX RAT variants and associated loaders in anti‑virus engines.

Suggested Tags

initial-access
cve-exploitation
dll-injection
shortcut-exploitation
domain-spoofing
data-exfiltration
badpilot-campaign
seashell-blizzard
plugx
phishing
zero-day
persistence
financial-gain
government-targeted
industrial-sector

Confidence Assessment

The assessment is based on a synthesis of publicly available intelligence feeds, industry reports, and documented technical artifacts attributed to Teleboyi. While the core capabilities—such as PlugX RAT usage, LNK-based delivery, zero‑day exploitation, and domain spoofing—are corroborated across multiple independent sources, certain identifiers (e.g., specific CVE usage or exact deployment dates) remain speculative due to limited confirmed evidence. The actor’s aliases list is wide but inconsistent; some of the purported nicknames appear conflated with other unrelated groups, creating uncertainty around group attribution. Key gaps include lack of definitive incident timestamps, precise malware hash evidence for all payloads, and explicit threat actor infrastructure mapping. Future investigations should focus on deep‑forensic analysis of compromised environments to confirm the presence of custom loaders, DLL injection patterns, and exfiltration protocols described herein.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT37
  2. www.trendmicro.com — Cited by web research for: CVE-2020-12812
  3. www.trendmicro.com — Cited by web research for: updata.dsqurey.com
  4. cloud.google.com — Cited by web research for: b.aqdrmf
  5. https://demo-cloud.space — Cited by AI analysis.
  6. https://attack.mitre.org/ — Cited by AI analysis.
  7. https://cisa.gov/ — Cited by AI analysis.

Intel Summary

3

Techniques

47

Tools

0

Campaigns

60

IOCs

0

Observed Data

2

Tactics

Tags

APT
China-linked
RAT activity
Espionage
initial-access
cve-exploitation
dll-injection
shortcut-exploitation
domain-spoofing
data-exfiltration
badpilot-campaign
seashell-blizzard
plugx
phishing
zero-day
persistence
financial-gain
government-targeted
industrial-sector

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.