Also known as: APT28, Pawn Storm, Fancy Bear, tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, MiniDionis, Chinastrats, Newscaster, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Sednit, BokBot, TG-0110, Hammertoss, Patchwork
SLIME88 operates as a sophisticated, China‑nexus threat actor that combines vulnerability exploitation with social engineering. In early April 2024 it weaponised the Apache ActiveMQ CVE‑2026‑34197 to inject malformed HTTP requests into the Jolokia API, triggering remote code execution on Linux servers. The payload delivered was SoxAgent RAT, which establishes a resilient SOCKS5 relay network named GOBLIN14 that channels traffic through AES‑encrypted tunnels and Cloudflare proxies. Beyond infrastructure exploitation, SLIME88 executes spear‑phishing campaigns targeting high‑profile sectors such as energy and manufacturing. These attacks use malicious Microsoft Word documents that exploit an EPS dictionary copy use‑after‑free flaw, as well as fake certificate installers sent via email to bypass initial defenses. The group then drops backdoor agents—AdaptixC2 or CobaltStrike—that provide extended persistence, remote code execution, and data exfiltration capabilities. SLIME88’s operational footprint spans a wide geographic range, with confirmed compromises in the United States, South Korea, India, France, Taiwan, and various other nations. The attackers often abuse default credentials (admin / admin) or leverage CVE‑2024‑32114 to bypass authentication on Apache components, demonstrating both technical prowess and opportunistic credential hijacking. The group’s approach shows a clear emphasis on stealth: encrypted C2 channels, self‑updating payloads that self‑delete upon completion, and the use of third‑party services like Cloudflare to obfuscate command‑and‑control nodes. These tactics enable prolonged covert operations against critical infrastructure and government entities.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
SLIME88 is a China‑aligned APT that leverages critical infrastructure CVEs—most notably Apache ActiveMQ CVE‑2026‑34197 and Office document vulnerabilities—to deploy its own RAT (SoxAgent) and other backdoors such as AdaptixC2. The group constructs an encrypted SOCKS5 relay network (GOBLIN14), masks C2 traffic with Cloudflare, and uses spear‑phishing campaigns that impersonate legitimate certificate installers to compromise energy, manufacturing, and state agencies across the US, Korea, India, France and beyond.
Goals & Targeting
SLIME88’s strategic objectives appear dual‑faced: financial gain through ransomware or data sale, and strategic sabotage of state‑critical systems. By targeting manufacturing, energy, telecommunications, and defense sectors in key geopolitical regions, the actor seeks to erode industrial resilience and secure sensitive operational intelligence. The reliance on low‑cost techniques—such as spear‑phishing and public CVE exploitation—indicates an intent to maintain a broad threat surface while keeping costs minimal. Ultimately SLIME88’s overarching aim is to position itself as a persistent backdoor operator that can be leveraged for extortion or geopolitical leverage.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SLIME88 demonstrates a high operational tempo, with rapid exploitation of newly disclosed CVEs and the ability to pivot across multiple sectors within weeks. Victims are primarily governmental agencies, defense contractors, energy utilities, and manufacturing facilities—organizations that typically run exposed messaging or monitoring software (e.g., Apache ActiveMQ). The group’s campaigns exhibit a modular architecture: initial compromise via spear‑phishing or public vulnerability, deployment of a lightweight RAT or backdoor, followed by lateral movement through privileged credentials and establishment of secure C2 tunnels. Recent attacks show the actor can pivot from Linux systems to Windows targets using the same weapon suite (IRONHALO/ELMER), underscoring its cross‑platform flexibility.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The core technical findings—such as the exploitation of Apache ActiveMQ CVE‑2026‑34197, deployment of SoxAgent, and use of Cloudflare for C2 obfuscation—are corroborated by multiple independent reports, lending high confidence to these capabilities. However, there remain gaps regarding exact campaign timelines (first/last seen), full enumeration of all target entities, and the extent of financial versus strategic objectives. Further intelligence on operational frequency and any possible attribution linkage between SLIME88 and known state actors would enhance threat assessment accuracy.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
47
Tools
0
Campaigns
37
IOCs
0
Observed Data
5
Tactics