Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SLIME88

Also known as: APT28, Pawn Storm, Fancy Bear, tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, MiniDionis, Chinastrats, Newscaster, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Sednit, BokBot, TG-0110, Hammertoss, Patchwork

Description

SLIME88 operates as a sophisticated, China‑nexus threat actor that combines vulnerability exploitation with social engineering. In early April 2024 it weaponised the Apache ActiveMQ CVE‑2026‑34197 to inject malformed HTTP requests into the Jolokia API, triggering remote code execution on Linux servers. The payload delivered was SoxAgent RAT, which establishes a resilient SOCKS5 relay network named GOBLIN14 that channels traffic through AES‑encrypted tunnels and Cloudflare proxies. Beyond infrastructure exploitation, SLIME88 executes spear‑phishing campaigns targeting high‑profile sectors such as energy and manufacturing. These attacks use malicious Microsoft Word documents that exploit an EPS dictionary copy use‑after‑free flaw, as well as fake certificate installers sent via email to bypass initial defenses. The group then drops backdoor agents—AdaptixC2 or CobaltStrike—that provide extended persistence, remote code execution, and data exfiltration capabilities. SLIME88’s operational footprint spans a wide geographic range, with confirmed compromises in the United States, South Korea, India, France, Taiwan, and various other nations. The attackers often abuse default credentials (admin / admin) or leverage CVE‑2024‑32114 to bypass authentication on Apache components, demonstrating both technical prowess and opportunistic credential hijacking. The group’s approach shows a clear emphasis on stealth: encrypted C2 channels, self‑updating payloads that self‑delete upon completion, and the use of third‑party services like Cloudflare to obfuscate command‑and‑control nodes. These tactics enable prolonged covert operations against critical infrastructure and government entities.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Healthcare
Telecommunications
Energy
Manufacturing
Aerospace
Education
Information technology
Media
Critical infrastructure
Maritime
Think tank
Pharmaceutical
Chemical
Hospitality
Mining
Entertainment
Legal services
Nuclear
Retail

Targeted Countries / Regions

US
CN
IN
GB
KR
JP
DE
RU
FR
IR
TW
SA
CA
IL
TR
AU
KZ
PK
VN
UA
PL
AE
SG
NL
BR
ES
IQ
BY
KP
IT
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 13 hours ago

Executive Summary

SLIME88 is a China‑aligned APT that leverages critical infrastructure CVEs—most notably Apache ActiveMQ CVE‑2026‑34197 and Office document vulnerabilities—to deploy its own RAT (SoxAgent) and other backdoors such as AdaptixC2. The group constructs an encrypted SOCKS5 relay network (GOBLIN14), masks C2 traffic with Cloudflare, and uses spear‑phishing campaigns that impersonate legitimate certificate installers to compromise energy, manufacturing, and state agencies across the US, Korea, India, France and beyond.

Goals & Targeting

SLIME88’s strategic objectives appear dual‑faced: financial gain through ransomware or data sale, and strategic sabotage of state‑critical systems. By targeting manufacturing, energy, telecommunications, and defense sectors in key geopolitical regions, the actor seeks to erode industrial resilience and secure sensitive operational intelligence. The reliance on low‑cost techniques—such as spear‑phishing and public CVE exploitation—indicates an intent to maintain a broad threat surface while keeping costs minimal. Ultimately SLIME88’s overarching aim is to position itself as a persistent backdoor operator that can be leveraged for extortion or geopolitical leverage.

Enhanced Description

Key Capabilities

  • Spear‑phishing via malicious Microsoft Word documents exploiting EPS dict copy use‑after‑free
  • Exploitation of CVE-2015-1701 local Windows privilege escalation
  • Exploitation of CVE-2026-34197 in Apache ActiveMQ through crafted Jolokia API requests for remote code execution
  • Use of default admin/admin credentials and CVE-2024-32114 to bypass authentication
  • Deployment of SoxAgent RAT on Linux, establishing SOCKS5 relay network GOBLIN14
  • Delivery and use of downloader IRONHALO and backdoor ELMER
  • Phishing campaigns with fake certificate installers targeting energy sector
  • Use of AdaptixC2 and CobaltStrike for persistence
  • Cloudflare‑proxied C2 to obfuscate IPs
  • AES‑encrypted dynamic tunnels
  • Self‑update and self‑deletion capabilities

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Command And Control
Persistence
Defense Evasion

ATT&CK Techniques

T1566.001
T1203
T1068
T1190
T1105
T1090
T1486
T1490

Software / Tooling

IRONHALO
ELMER
SoxAgent RAT
GOBLIN14
AdaptixC2
CobaltStrike

Campaigns & Victims

SLIME88 demonstrates a high operational tempo, with rapid exploitation of newly disclosed CVEs and the ability to pivot across multiple sectors within weeks. Victims are primarily governmental agencies, defense contractors, energy utilities, and manufacturing facilities—organizations that typically run exposed messaging or monitoring software (e.g., Apache ActiveMQ). The group’s campaigns exhibit a modular architecture: initial compromise via spear‑phishing or public vulnerability, deployment of a lightweight RAT or backdoor, followed by lateral movement through privileged credentials and establishment of secure C2 tunnels. Recent attacks show the actor can pivot from Linux systems to Windows targets using the same weapon suite (IRONHALO/ELMER), underscoring its cross‑platform flexibility.

IOC Patterns

  • domain
  • file
  • email
  • ip-v4
  • hash-sha256

Recommended Actions

  • Apply patches for Microsoft Office to mitigate malicious document exploitation.
  • Patch local Windows systems against CVE‑2015‑1701 and enforce least privilege on administrative accounts.
  • Update or disable the Jolokia API endpoint in Apache ActiveMQ, applying CVE-2026-34197 mitigations promptly.
  • Enforce strong authentication (e.g., change default admin credentials) for all messaging services.
  • Deploy network segmentation to isolate critical manufacturing and IT infrastructure from exposed services.
  • Implement detection rules that flag SoxAgent or CobaltStrike activity and anomalous outbound traffic through Cloudflare proxies.
  • Conduct regular vulnerability scans for CVE-2024-32114 and other Apache ActiveMQ exploits.
  • Monitor broker logs for malformed XML requests and HTTP traffic patterns indicative of exploitation attempts.
  • Set up blocking of known C2 IPs and Cloudflare‑proxied addresses at the perimeter firewall.
  • Provide spear‑phishing awareness training to users, emphasizing document and certificate source verification.

Suggested Tags

SLIME88
APT3
BunnyEagle
Gothic Panda
TG-0110
Charming Kitten
Parastoo
Newscaster
China-based APT groups
Government organizations
Defense technology sectors
State‑Sponsored
CVE Exploitation
Apache ActiveMQ
Remote Code Execution
SoxAgent RAT
GOBLIN14
Linux RAT
SoxAgent
APT28
Remote Access Proxy
Phishing
Cloudflare
Energy Sector Target
Malicious XML

Confidence Assessment

The core technical findings—such as the exploitation of Apache ActiveMQ CVE‑2026‑34197, deployment of SoxAgent, and use of Cloudflare for C2 obfuscation—are corroborated by multiple independent reports, lending high confidence to these capabilities. However, there remain gaps regarding exact campaign timelines (first/last seen), full enumeration of all target entities, and the extent of financial versus strategic objectives. Further intelligence on operational frequency and any possible attribution linkage between SLIME88 and known state actors would enhance threat assessment accuracy.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 15 SHA-256 Hash 3 IPv4 Address 1 Filename 1

References

Intel Summary

8

Techniques

47

Tools

0

Campaigns

37

IOCs

0

Observed Data

5

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
China
CyberEspionage
EnergySector
Manufacturing
SLIME88
APT3
BunnyEagle
Gothic Panda
TG-0110
Charming Kitten
Parastoo
Newscaster
China-based APT groups
Government organizations
Defense technology sectors
State‑Sponsored
CVE Exploitation
Apache ActiveMQ
Remote Code Execution
SoxAgent RAT
GOBLIN14
Linux RAT
SoxAgent
APT28
Remote Access Proxy
Cloudflare
Energy Sector Target
Malicious XML

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.