Also known as: TG-3279, Winnti Umbrella, China Cracking Group, tracked as, indicating active exploitation, as Crown jewels, 560048, RevivalStone, PRIVATELOG
The PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen Authenticode-signing certificates. Snorre Fagerland of Blue Coat Systems first coined the term PassCV in a blog post. His post provides a good introduction to the group and covers some of the older infrastructure, stolen code-signing certificate reuse, and other connections associated with the PassCV malware. There are several clues alluding to the possibility that multiple groups may be utilizing the same stolen signing certificates, but at this time SPEAR believes the current attacks are more likely being perpetrated by a single group employing multiple publicly available Remote Administration Tools (RATs). The PassCV group has been operating with continued success and has already started to expand their malware repertoire into different off-the-shelf RATs and custom code. SPEAR identified eighteen previously undisclosed stolen Authenticode certificates. These certificates were originally issued to companies and individuals scattered across China, Taiwan, Korea, Europe, the United States and Russia. In this post we expand the usage of the term ‘PassCV’ to encompass the malware mentioned in the Blue Coat Systems report, as well as the APT group behind the larger C2 infrastructure and stolen Authenticode certificates. We’d like to share some of our findings as they pertain to the stolen certificates, command and control infrastructure, and some of the newer custom RATs they’ve begun development on.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
PassCV is a highly active cyber threat group primarily involved in espionage activities. They are known for leveraging stolen Authenticode-signing certificates and using a variety of Remote Administration Tools (RATs). Their operations have expanded to include custom malware and off-the-shelf tools, targeting sectors such as gaming and technology.
Goals & Targeting
PassCV's strategic objectives appear to be centered on espionage and intelligence-gathering activities, particularly within the gaming and technology sectors. Their use of stolen certificates and diverse toolset suggests an intent to remain undetected while compromising sensitive data. The group has targeted victims across multiple regions, including Asia, Europe, and North America, indicating a global targeting strategy.
Enhanced Description
PassCV, also known as TG-3279, Winnti Umbrella, or China Cracking Group, is a sophisticated cyber threat actor with a primary focus on espionage. The group has demonstrated significant success in compromising systems by utilizing stolen code-signing certificates to masquerade their malicious activities as legitimate software. Snorre Fagerland of Blue Coat Systems first documented PassCV's activities, highlighting their use of these stolen certificates and their connection to multiple campaigns. PassCV is believed to operate with a single group structure despite the variety of tools employed, including custom RATs and off-the-shelf solutions. The group has continuously evolved its tactics, targeting industries such as gaming and technology through both malware development and infrastructure exploitation.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
PassCV has been active for several years, with campaigns involving the use of stolen certificates and various RATs. Their operations have included targeting gaming companies, software developers, and other industries with high-value intellectual property. Notable tactics include the use of legitimate-looking signed binaries to distribute malware, ensuring persistence, and establishing robust command-and-control (C2) infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in_passcv's involvement in espionage and malware distribution. Limited visibility into their exact TTPs due to evolving nature of operations, but strong evidence links them to stolen certificates and RAT usage.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
57
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics