Also known as: DeputyDog, tracked as, APT37, Ricochet Chollima, ScarCruft, Reaper Group, Spring Dragon, Billbug, manufacturing, telecom, Vietnam, Hong Kong, Rare Wolf, Belarusian, Ukrainian industrial enterprises, Gamaredon, verifying the signature, Shadows, Comet, Darkstar, to carry out attacks, APT44, BlackEnergy, PHANTOM, UAC-0133, Blue Echidna, Sandworm, UNK_CraftyCamel, ZDI-25-148, Thrip
Teleboyi, also referred to in open-source intelligence as DeputyDog or APT37 in some reports, emerged as a highly adaptable threat actor that has consistently exploited both software vulnerabilities and social engineering tactics. The group’s hallmark signature is the use of PlugX RAT modules delivered via custom C# loaders that modify registry entries to disable autoruns, drop secondary payloads, and evade Windows Mark‑of‑the Web protection through double‑archiving techniques. Operationally, Teleboyi combines automated exploitation pipelines with targeted phishing emails aimed at Chinese‑speaking professional audiences across industries in Asia‑Pacific. These campaigns employ malicious LNK file attachments containing hidden command‑line arguments to trigger short‑lived PowerShell scripts (VeilShell Trojan) and DLL execution, followed by the installation of a download‑and‑run component that fetches additional binaries over HTTP/2 or QUIC. The actor also registers domain names mimicking legitimate targets, thereby facilitating credential harvesting via web shells. Once compromised, Teleboyi often injects malicious code into svchost.exe to maintain persistence and exfiltrate data using custom Go‑written modules that perform HTTP GET/POST requests to back‑end C&C servers. Their toolkit includes a broad spectrum of commercial exploitation frameworks such as Impacket, Mythic, and quasarRAT, alongside bespoke loaders like GuLoader and Lumma Stealer. In recent campaigns, the group demonstrated an advanced capability to manipulate Windows shortcut (.lnk) files to bypass local application controls and execute stealthy payloads. These tactics have allowed Teleboyi to infiltrate key sectors, including energy, defense, and telecommunications, often exploiting widely publicized CVEs such as CVE‑2024‑1709, CVE‑2023‑48788 and CVE‑2021‑34473. Overall, Teleboyi operates with a clear commercial agenda while simultaneously leveraging the strategic advantages of zero‑day exploits to maintain an evolving threat posture across multiple continents.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Teleboyi is a financially motivated threat actor, presumed headquartered in China, that employs PlugX-based RATs and custom obfuscated loaders to infiltrate high‑value targets across multiple sectors worldwide. The group leverages zero‑day vulnerabilities (e.g., 7‑Zip CVE‑2025‑0411) alongside phishing campaigns targeting Chinese-speaking users, using malicious LNK files, DLL injections, and domain spoofing to gain initial access and establish persistence. Their operations span government, financial services, telecommunications, manufacturing and critical infrastructure across continents, evidencing a broad geographic reach and well‑organized campaign structure.
Goals & Targeting
Teleboyi’s strategic objective is primarily financial gain, achieved by targeting sectors that retain large amounts of intellectual and proprietary data. The actor focuses on high‑profile industries—government agencies, manufacturing firms, telecommunications providers, energy utilities and critical infrastructure—to maximize the value of stolen credentials, trade secrets and financial information. The group deliberately expands its reach across both geopolitical regions (e.g., North America, Europe, East Asia) and industry verticals, indicating a pursuit of diverse revenue streams. By exploiting known CVEs in public‑facing software—such as Microsoft applications, internet servers, and network appliances—Teleboyi lowers the barrier to entry while simultaneously leveraging phishing campaigns tailored to local languages, improving the likelihood of successful credential compromise. In addition to direct monetary theft, Teleboyi’s use of plug‑in RATs and data exfiltration modules suggests secondary objectives such as strategic information gathering to facilitate future attacks or blackmail. The actor’s ability to obscure execution through DLL injection and shortcut exploitation enables long‑term persistence, thereby enabling recurring revenue opportunities. Keycapabilities: - Phishing campaigns targeting Chinese‑speaking users across Asia‑Pacific industries - Exploitation of zero‑day vulnerabilities such as CVE‑2025‑0411 (7‑Zip) and other public software flaws for initial access - Use of obfuscated C# loaders that modify registry keys to disable autoruns and drop second‑stage payloads - Execution via LNK file attachments, DLL execution, PowerShell scripts, and web shells - Deployment of additional malicious binaries over HTTP/2, QUIC, and standard HTTP protocols - Exfiltration of system data using GET and POST over multiple HTTP versions (1.1 – 3.0) - Evasion of Windows Mark‑of‑the Web protection through double archiving techniques - Initial access via exploitation of public-facing software vulnerabilities - DLL injection into svchost.exe to load malicious modules and gain persistence - Crafting of .lnk files with hidden command‑line arguments for covert execution - Domain spoofing by registering domain names that mimic victim domains
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Teleboyi has conducted a series of coordinated campaigns—most recently dubbed the BadPilot operation—across multiple nationalities, exploiting high‑profile CVEs such as CVE‑2024‑1709, CVE‑2023‑48788 and CVE‑2021‑34473 to compromise public‑facing applications. The group frequently uses a zero‑day in the widely deployed 7‑Zip utility (CVE‑2025‑0411) to bypass initial defenses. Typical attack vectors involve either phishing emails bearing malicious LNK attachments or direct exploitation of remotely exposed software via known vulnerabilities. Once foothold is achieved, Teleboyi deploys a custom C# loader that modifies registry keys, disables autoruns and drops secondary stages (including PlugX RAT modules), followed by DLL injection into svchost.exe for persistence. The actor’s use of domain spoofing—registering innocuous domains such as updata.dsqurey.com that replicate legitimate vendor names—highlights an emphasis on supply‑chain or credential‑phishing attacks, often integrated with web shell deployments. Teleboyi operates with a high operational tempo, moving quickly from initial compromise to exfiltration and persistence, while maintaining a broad geographic footprint covering the US, UK, EU, Russia, Ukraine, Vietnam, China, Japan and several other nations. Victims have primarily been in government agencies, financial services, telecommunications, energy utilities and manufacturing sectors—demonstrating a clear pattern of targeting high‑value targets that are likely to yield significant illicit returns. ioc_patterns:
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on a synthesis of publicly available intelligence feeds, industry reports, and documented technical artifacts attributed to Teleboyi. While the core capabilities—such as PlugX RAT usage, LNK-based delivery, zero‑day exploitation, and domain spoofing—are corroborated across multiple independent sources, certain identifiers (e.g., specific CVE usage or exact deployment dates) remain speculative due to limited confirmed evidence. The actor’s aliases list is wide but inconsistent; some of the purported nicknames appear conflated with other unrelated groups, creating uncertainty around group attribution. Key gaps include lack of definitive incident timestamps, precise malware hash evidence for all payloads, and explicit threat actor infrastructure mapping. Future investigations should focus on deep‑forensic analysis of compromised environments to confirm the presence of custom loaders, DLL injection patterns, and exfiltration protocols described herein.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
47
Tools
0
Campaigns
60
IOCs
0
Observed Data
2
Tactics