Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: tracked as, Charming Kitten, ESET said, Newscaster, Parastoo, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, NEWSCASTER, APT35, RICH ION

Description

Titan emerged in early 2026, quickly establishing itself as a financially driven criminal collective with ambitions that span ransomware payouts to covert intelligence gathering. Their operational model relies on a blend of social engineering—primarily spear‑phishing—and exploitation of known vulnerabilities, notably the unauthenticated template injection (CVE‑2023‑22527) in Atlassian Confluence and network device weaknesses like Check Point IKEv1 CVE‑2026‑50751 and ConnectWise ScreenConnect CVE‑2024‑1708. Once a foothold is gained, attackers deploy custom binaries such as *titan‑edge* and *libgoworkerd.so*, manipulate environment variables (e.g., misspelled LD_LIBRARY_PATH) and SSH authorized_keys to achieve persistence and evade detection. Beyond traditional RCE, Titan’s post‑compromise activities include dynamic linker hijacking for privilege escalation, binding compromised hosts to an attacker‑controlled ID on a DePIN network where they initiate cryptomining operations using the aleo‑pool client. They also stage large volumes of data in temporary directories before proceeding with ransomware encryption, often extracting engineering designs or other high‑value intelligence from government and defense contractors. Titan’s toolkit is modular: shell scripts automate download and execution; custom TLS‑based command & control channels use web protocols (T1071.001), while remote management tools such as ConnectWise ScreenConnect are exploited to establish lateral movement paths. Their campaigns demonstrate a consistent pattern of leveraging high‑impact CVEs, coupling them with stealthy persistence layers that can remain active for extended periods before triggering ransomware payloads.

TTP Summary

Fake Social Media Account

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Defense
Financial services
Healthcare
Media
Transportation
Construction
Food agriculture
Critical infrastructure
Manufacturing
Telecommunications
Non profit

Targeted Countries / Regions

UA
US
AE
RU
IL
CN
DE
BR
GB
IR
FR
JP
PL
NL

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 4 hours ago

Executive Summary

Titan is a medium‑sophistication threat actor that combines ransomware, cryptomining and espionage capabilities to target both commercial and defense organizations worldwide. They exploit unpatched public applications such as Atlassian Confluence and Check Point gateways, then implant persistent backdoors configured for wide‑scale data staging and eventual encryption of critical assets.

Goals & Targeting

Titan’s strategic objectives blend immediate financial gain from ransom payments and cryptomining revenue with longer‑term espionage gains. By targeting sectors such as government, defense, finance, healthcare, media, critical infrastructure, and telecommunications across a broad geographic footprint—especially the US, Ukraine, Russia, and Israel—they aim to compromise high-visibility platforms for both monetary extraction and information theft. The actor’s use of spear‑phishing and exploitation of well-known open‑source or vendor‑supplied software underlines their intent to maximize attack surface while minimizing effort.

Enhanced Description

Key Capabilities

  • Exploit public-facing application vulnerabilities (e.g., CVE‑2023‑22527 template injection)
  • Deploy remote shell scripts for payload delivery and execution via curl
  • Install proprietary Titan edge binaries (titan‑edge, libgoworkerd.so) and configure them
  • Persist via dynamic linker hijacking or environment variable manipulation (LD_LIBRARY_PATH)
  • Manipulate SSH authorized_keys for persistence or privilege escalation
  • Bind compromised hosts to attacker-controlled IDs in the Titan DePIN network for cryptomining
  • Engage in cryptomining operations using DePIN platforms such as aleo‑pool client
  • Initial access via spear‑phishing campaigns and phishing emails
  • Implement persistent backdoor communication with a command-and-control center using web protocols (T1071.001)
  • Exploit network infrastructure vulnerabilities (Check Point IKEv1 CVE‑2026‑50751, ConnectWise ScreenConnect CVE‑2024‑1708)
  • Stage large volumes of data in temporary directories before ransomware encryption
  • Target exfiltration of engineering designs and military infrastructure details

MITRE ATT&CK Tactics

Initial Access
Discovery
Execution
Persistence
Command and Control
Exfiltration

ATT&CK Techniques

T1082
T1083
T1057
T1059.004
T1574.006
T1098.004
T1105
T1071.001
T1566.001
T1190
T1203
T1071

Software / Tooling

Titan Edge Node
libGoworker.so
aleo-pool Client
Shell Scripts a0-a7
Titan Ransomware
Check Point Security Gateway
ConnectWise ScreenConnect

Campaigns & Victims

Titan’s earliest campaign, dubbed "Mezta Corporativo," leveraged a known CVE in Atlassian Confluence to deploy ransomware against a manufacturing client, while subsequent operations named after industries (e.g., "DFI AMERICA" and "Groupe CRIT SA") demonstrate methodical expansion into finance, defense and media. The actor typically conducts brief but intense action windows—often within 24–48 hours of initial access—to stage data in temporary folders, exfiltrate targets of strategic interest, and deploy ransomware before cleaning up traces or shifting to mining operations. Their repeated exploitation of vendor CVEs indicates a focus on high-value attacks that require minimal development effort yet yield significant financial returns. Notably, Titan’s use of cryptomining via DePIN nodes signals an evolution from pure ransomware to hybrid financially-driven operations, providing diversified revenue streams while maintaining the option for covert data gathering from state or critical infrastructure networks.

IOC Patterns

  • Domain names
  • IPv4 addresses
  • File hashes
  • Email addresses

Recommended Actions

  • Apply patches to Atlassian Confluence to remediate CVE‑2023‑22527 and enforce least privilege access controls
  • Audit and harden Check Point Security Gateways against CVE‑2026‑50751; update VPN firmware
  • Patch ConnectWise ScreenConnect software and remediate CVE‑2024‑1708 vulnerability
  • Block outbound traffic to known Titan DePIN mining endpoints (e.g., aleo-pool clients) and cryptomining pools
  • Monitor /tmp and ProgramData directories for unexpected binaries such as titan‑edge or libgoworkerd.so
  • Inspect shell script execution requests from external IPs and validate script integrity
  • Track changes to LD_LIBRARY_PATH and other critical environment variables for hijacking indicators
  • Review SSH authorized_keys files regularly; restrict write permissions to administrators only
  • Deploy detection rules for RCE payload signatures, template injection patterns, and anomalous file creations across endpoints
  • Implement spear‑phishing awareness training coupled with advanced email filtering and anti-spam solutions
  • Detect and block large-volume data staging in temporary folders as an early warning for ransomware activity

Suggested Tags

cryptomining
RCE exploitation
template injection
CVE-2023-22527
Atlassian Confluence
Titan Network
DePIN
shell script attack
dynamic linker hijacking
SSH authorized_keys manipulation
APT
China
Chinese State Actor
Spear Phishing
Backdoor Implant
VPN Exploit
ScreenConnect Vulnerability
Check Point Vulnerability
Ransomware
Titan Ransomware

Confidence Assessment

The available data provides a moderately high confidence view of Titan’s capabilities and objectives, corroborated by documented CVE exploitation and observed ransomware deployments across diverse sectors. However, gaps remain regarding the full extent of their infrastructure, attribution certainty beyond the Chinese state actor label, and detailed operational tempo for future campaigns. Continuous monitoring and threat hunting are recommended to close these knowledge gaps.

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. www.trendmicro.com — Cited by web research for: T1190
  2. securityarsenal.com — Cited by web research for: ScreenConnect
  3. cloud.google.com — Cited by web research for: REvil
  4. www.splunk.com — Cited by web research for: Aurora
  5. www.dexpose.io — Cited by web research for: Qilin
  6. pmc.ncbi.nlm.nih.gov — Cited by web research for: Lorenz
  7. https://nvd.nist.gov/vuln/detail/CVE-2023-22527 — Cited by AI analysis.
  8. https://www.checkpoint.com/learn/security-advisories/cve-2026-50751/ — Cited by AI analysis.
  9. https://support.connectwise.com/customer/en/portal/articles/3335955-screenconnect-cve-2024-1708 — Cited by AI analysis.

Intel Summary

12

Techniques

56

Tools

15

Campaigns

43

IOCs

0

Observed Data

6

Tactics

Tags

cryptomining
RCE exploitation
template injection
CVE-2023-22527
Atlassian Confluence
Titan Network
DePIN
shell script attack
dynamic linker hijacking
SSH authorized_keys manipulation
APT
China
Chinese State Actor
Spear Phishing
Backdoor Implant
VPN Exploit
ScreenConnect Vulnerability
Check Point Vulnerability
Ransomware
Titan Ransomware

Details

MITRE ID
APT35
Type
Criminal
Sophistication
Medium
Resource Level
Government
Primary Motivation
Organizational gain
Country of Origin
Russia (RU)
Confidence
80%
First Seen
Apr 14, 2026
Last Seen
Jul 21, 2026
Added
May 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.