Also known as: Actor240820, other aliases, several other aliases, Jumpy Pisces, Gothic Panda, UPS Team, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, APT28, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Turla, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, LummaC2 Stealer, the ALPHV Ransomware Group, ALPHV Blackcat, Comment Crew, MenuPass, Red Apollo, Stone Panda, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene, Velvet Chollima, Sparkling Pisces, HIDDEN COBRA, Turbine Panda, Hippo Team, JerseyMikes, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon
ChainedShark has been observed since at least 2014, evolving from typical cybercriminal operations into a state‑backed actor capable of sophisticated supply‑chain attacks and web compromises (SWC). The group’s primary objectives include intellectual property theft from China’s scientific research community and broad financial exploitation through custom malware deployments. By combining spear‑phishing campaigns with zero‑day vulnerabilities, ChainedShark can infiltrate high‑value targets with minimal detection. The attacker leverages an extensive toolkit of both proprietary and open‑source malware, including banking trojans (IcedID/BokBot), ransomware (BlackCat/ALPHV), and fileless execution frameworks such as Brute Ratel and Cobalt Strike. Their attack chains are meticulously engineered: initial intrusion via phishing or exploitation of public‑facing services, followed by credential harvesting, lateral movement, persistence establishment, and eventual data exfiltration or ransomware deployment. Noteworthy is the group’s use of advanced post‑exploitation techniques such as PowerShell abuse (T1059.001) and supply‑chain compromise to distribute malicious code via legitimate third‑party vendor channels. This dual approach allows ChainedShark to bypass traditional perimeter defenses while maintaining a low profile. Overall, ChainedShark represents a significant threat actor capable of both targeted intelligence gathering against strategic sectors and large‑scale financial exploitation through ransomware and banking trojan activity.
Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ChainedShark is a sophisticated actor primarily targeting Chinese scientific research but with recent evidence of broader activity across government, financial, and critical infrastructure sectors worldwide. The group uses spear‑phishing, zero‑day exploits, and supply‑chain compromise to deliver custom banking trojans, fileless malware, and ransomware for both data exfiltration and monetary gain. Its operations demonstrate a mature, multi‑year operational tempo with advanced post‑exploitation capabilities.
Goals & Targeting
ChainedShark’s strategic objectives are twofold: first, to extract valuable intellectual property and confidential data from Chinese scientific research institutions—and by extension, other high‑value organizations—using stealthy supply‑chain and spear‑phishing vectors; second, to monetize compromised assets through ransomware and credential‑stealing banking trojans across multiple geopolitical regions. The actor’s targeting profile centers on sectors deemed critical for national security or economic competitiveness, with a proven ability to adapt its TTPs to varied regulatory environments.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ChainedShark has maintained a multi‑year campaign footprint, targeting government, financial, and critical infrastructure entities across the United States, China, Russia, Iran, and other nations. The group frequently employs supply‑chain or web compromise vectors to disseminate bespoke payloads, immediately leveraging power‑shell and fileless techniques for lateral movement. Recent activity indicates a strategic pivot toward ransomware-as-a-service delivery while still retaining robust credential‑stealing capabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The compiled intelligence offers moderate confidence in ChainedShark’s attribution and tactics, given corroboration across multiple independent sources. However, gaps remain regarding the precise attribution chain (i.e., direct links to specific state actors), exact deployment architectures for supply‑chain attacks, and detailed incident timestamps across all countries listed.
No campaigns linked yet.
No observed data linked yet.
6
Techniques
57
Tools
0
Campaigns
40
IOCs
0
Observed Data
4
Tactics