Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ChainedShark

Also known as: Actor240820, other aliases, several other aliases, Jumpy Pisces, Gothic Panda, UPS Team, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, APT28, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Turla, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, LummaC2 Stealer, the ALPHV Ransomware Group, ALPHV Blackcat, Comment Crew, MenuPass, Red Apollo, Stone Panda, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene, Velvet Chollima, Sparkling Pisces, HIDDEN COBRA, Turbine Panda, Hippo Team, JerseyMikes, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon

Description

ChainedShark has been observed since at least 2014, evolving from typical cybercriminal operations into a state‑backed actor capable of sophisticated supply‑chain attacks and web compromises (SWC). The group’s primary objectives include intellectual property theft from China’s scientific research community and broad financial exploitation through custom malware deployments. By combining spear‑phishing campaigns with zero‑day vulnerabilities, ChainedShark can infiltrate high‑value targets with minimal detection. The attacker leverages an extensive toolkit of both proprietary and open‑source malware, including banking trojans (IcedID/BokBot), ransomware (BlackCat/ALPHV), and fileless execution frameworks such as Brute Ratel and Cobalt Strike. Their attack chains are meticulously engineered: initial intrusion via phishing or exploitation of public‑facing services, followed by credential harvesting, lateral movement, persistence establishment, and eventual data exfiltration or ransomware deployment. Noteworthy is the group’s use of advanced post‑exploitation techniques such as PowerShell abuse (T1059.001) and supply‑chain compromise to distribute malicious code via legitimate third‑party vendor channels. This dual approach allows ChainedShark to bypass traditional perimeter defenses while maintaining a low profile. Overall, ChainedShark represents a significant threat actor capable of both targeted intelligence gathering against strategic sectors and large‑scale financial exploitation through ransomware and banking trojan activity.

TTP Summary

Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Non profit
Critical infrastructure
Education
Energy
Media
Aerospace
Manufacturing
Maritime
Think tank
Information technology
Chemical
Aviation
Hospitality
Legal services
Pharmaceutical
Gaming
Utilities
Mining
Transportation
Retail
Nuclear
Entertainment
Aerospace & defense
Legal

Targeted Countries / Regions

US
CN
RU
IN
GB
IR
KR
JP
DE
SA
TW
TR
FR
CA
IL
BR
UA
VN
AU
KZ
PK
KP
PL
AE
SG
NL
ES
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 hours ago

Executive Summary

ChainedShark is a sophisticated actor primarily targeting Chinese scientific research but with recent evidence of broader activity across government, financial, and critical infrastructure sectors worldwide. The group uses spear‑phishing, zero‑day exploits, and supply‑chain compromise to deliver custom banking trojans, fileless malware, and ransomware for both data exfiltration and monetary gain. Its operations demonstrate a mature, multi‑year operational tempo with advanced post‑exploitation capabilities.

Goals & Targeting

ChainedShark’s strategic objectives are twofold: first, to extract valuable intellectual property and confidential data from Chinese scientific research institutions—and by extension, other high‑value organizations—using stealthy supply‑chain and spear‑phishing vectors; second, to monetize compromised assets through ransomware and credential‑stealing banking trojans across multiple geopolitical regions. The actor’s targeting profile centers on sectors deemed critical for national security or economic competitiveness, with a proven ability to adapt its TTPs to varied regulatory environments.

Enhanced Description

Key Capabilities

  • Spearfishing
  • Zero-day exploitation
  • SQL injection
  • Custom malware development
  • Banking trojan deployment
  • Ransomware campaigns orchestration
  • Initial access via phishing or spear‑phishing
  • Credential harvesting
  • Fileless malware deployment
  • Advanced post‑exploitation frameworks (Brute Ratel, Cobalt Strike)
  • Supply‑chain compromise

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Persistence
Credential Access
Defense Evasion

ATT&CK Techniques

T1566.001
T1190
T1068
T1566.002
T1078
T1059.001

Software / Tooling

SUNBURST
Kazuar
Dridex
IcedID (BokBot)
Latrodectus downloader
Lotus loader family
Brute Ratel
Cobalt Strike
Emotet

Campaigns & Victims

ChainedShark has maintained a multi‑year campaign footprint, targeting government, financial, and critical infrastructure entities across the United States, China, Russia, Iran, and other nations. The group frequently employs supply‑chain or web compromise vectors to disseminate bespoke payloads, immediately leveraging power‑shell and fileless techniques for lateral movement. Recent activity indicates a strategic pivot toward ransomware-as-a-service delivery while still retaining robust credential‑stealing capabilities.

IOC Patterns

  • Phishing email indicators
  • Vulnerability exploitation patterns
  • SQL injection vectors
  • Malware signatures
  • Domain indicators
  • File hash-MD5

Recommended Actions

  • Implement phishing awareness training and anti‑phishing solutions to mitigate spear‑phishing attacks
  • Enforce multi‑factor authentication across all user accounts to protect against credential harvesting
  • Deploy endpoint detection and response (EDR) tools capable of detecting fileless malware, PowerShell abuse, and Cobalt Strike activity
  • Block known banking trojan domains and IP addresses associated with Dridex, IcedID/BokBot, and Emotet
  • Monitor for supply‑chain compromise indicators and third‑party service vulnerabilities

Suggested Tags

APT group
State-sponsored
China-based
North Korea-linked
Spear-phishing
Zero-day vulnerability exploitation
SQL injection
Russia‑based
Cybercriminal syndicate
Banking trojans
Ransomware-as-a-Service
Downloader
Botnet
Evil Corp
Lunar Spider
Indrik Spider
Mummy Spider

Confidence Assessment

The compiled intelligence offers moderate confidence in ChainedShark’s attribution and tactics, given corroboration across multiple independent sources. However, gaps remain regarding the precise attribution chain (i.e., direct links to specific state actors), exact deployment architectures for supply‑chain attacks, and detailed incident timestamps across all countries listed.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 16 Filename 3 MD5 Hash 1

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. unit42.paloaltonetworks.com — Cited by web research for: Web Shells
  3. misp-galaxy.org — Cited by web research for: Void
  4. nsfocusglobal.com — Cited by web research for: CVE-2025-2783
  5. https://malpedia.caad.fkie.fraunhofer.de/details/win.sunburst — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.kazuar — Cited by AI analysis.
  7. https://x.com/Cyber_O51NT/status/2022324728099213350 — Cited by AI analysis.

Intel Summary

6

Techniques

57

Tools

0

Campaigns

40

IOCs

0

Observed Data

4

Tactics

Tags

APT
Critical Infrastructure
Data Exfiltration
espionage
China-linked
scientific research
Custom malware
APT group
State-sponsored
China-based
North Korea-linked
Spear-phishing
Zero-day vulnerability exploitation
SQL injection
Russia‑based
Cybercriminal syndicate
Banking trojans
Ransomware-as-a-Service
Downloader
Botnet
Evil Corp
Lunar Spider
Indrik Spider
Mummy Spider

Details

MITRE ID
APT26
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.