Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors PassCV

Also known as: TG-3279, Winnti Umbrella, China Cracking Group, tracked as, indicating active exploitation, as Crown jewels, 560048, RevivalStone, PRIVATELOG

Description

The PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen Authenticode-signing certificates. Snorre Fagerland of Blue Coat Systems first coined the term PassCV in a blog post. His post provides a good introduction to the group and covers some of the older infrastructure, stolen code-signing certificate reuse, and other connections associated with the PassCV malware. There are several clues alluding to the possibility that multiple groups may be utilizing the same stolen signing certificates, but at this time SPEAR believes the current attacks are more likely being perpetrated by a single group employing multiple publicly available Remote Administration Tools (RATs). The PassCV group has been operating with continued success and has already started to expand their malware repertoire into different off-the-shelf RATs and custom code. SPEAR identified eighteen previously undisclosed stolen Authenticode certificates. These certificates were originally issued to companies and individuals scattered across China, Taiwan, Korea, Europe, the United States and Russia. In this post we expand the usage of the term ‘PassCV’ to encompass the malware mentioned in the Blue Coat Systems report, as well as the APT group behind the larger C2 infrastructure and stolen Authenticode certificates. We’d like to share some of our findings as they pertain to the stolen certificates, command and control infrastructure, and some of the newer custom RATs they’ve begun development on.

Goals & Targeting

Targeted Sectors

Gaming
Financial services
Government
Energy
Pharmaceutical
Telecommunications
Media
Manufacturing
Healthcare
Defense
Retail
Utilities
Aerospace
Construction
Aviation
Education

Targeted Countries / Regions

CN
US
IN
FR
IT
JP
KR
PK
TW
TR
NG
GB
RU
DE
BR
SG
KZ
NL

AI Analysis

· 1 week ago

Executive Summary

PassCV is a highly active cyber threat group primarily involved in espionage activities. They are known for leveraging stolen Authenticode-signing certificates and using a variety of Remote Administration Tools (RATs). Their operations have expanded to include custom malware and off-the-shelf tools, targeting sectors such as gaming and technology.

Goals & Targeting

PassCV's strategic objectives appear to be centered on espionage and intelligence-gathering activities, particularly within the gaming and technology sectors. Their use of stolen certificates and diverse toolset suggests an intent to remain undetected while compromising sensitive data. The group has targeted victims across multiple regions, including Asia, Europe, and North America, indicating a global targeting strategy.

Enhanced Description

PassCV, also known as TG-3279, Winnti Umbrella, or China Cracking Group, is a sophisticated cyber threat actor with a primary focus on espionage. The group has demonstrated significant success in compromising systems by utilizing stolen code-signing certificates to masquerade their malicious activities as legitimate software. Snorre Fagerland of Blue Coat Systems first documented PassCV's activities, highlighting their use of these stolen certificates and their connection to multiple campaigns. PassCV is believed to operate with a single group structure despite the variety of tools employed, including custom RATs and off-the-shelf solutions. The group has continuously evolved its tactics, targeting industries such as gaming and technology through both malware development and infrastructure exploitation.

Key Capabilities

  • Exploitation of stolen code-signing certificates
  • Use of Remote Administration Tools (RATs)
  • Custom malware development
  • Leverage off-the-shelf tools

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Defense Evasion

Software / Tooling

Custom RATs
Off-the-shelf RATs (e.g., Meterpreter, Quasar Rat)

Campaigns & Victims

PassCV has been active for several years, with campaigns involving the use of stolen certificates and various RATs. Their operations have included targeting gaming companies, software developers, and other industries with high-value intellectual property. Notable tactics include the use of legitimate-looking signed binaries to distribute malware, ensuring persistence, and establishing robust command-and-control (C2) infrastructure.

IOC Patterns

  • Use of stolen Authenticode certificates for signing malicious binaries
  • Distribution of RATs via phishing or direct compromise
  • Presence of custom malware with specific signatures

Recommended Actions

  • Implement strict certificate management practices to detect and block use of stolen certificates.
  • Monitor for suspicious processes and unusual activity indicative of RAT usage.
  • Conduct regular network traffic analysis to identify C2 infrastructure patterns.

Suggested Tags

APT
espionage
cyber-espionage
gaming
technology

Confidence Assessment

High confidence in_passcv's involvement in espionage and malware distribution. Limited visibility into their exact TTPs due to evolving nature of operations, but strong evidence links them to stolen certificates and RAT usage.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 20

References

  1. www.cyfirma.com — Cited by web research for: as Crown jewels
  2. securityaffairs.com — Cited by web research for: RevivalStone
  3. apt.etda.or.th — Cited by web research for: ZxShell
  4. cloud.google.com — Cited by web research for: aqdrmf-rymPhb-ibnC6b.aqdrmf

Intel Summary

40

Techniques

57

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

Ransomware
APT
Backdoor / C2
espionage
cyber-espionage
gaming
technology

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
C
Confidence
50%
Added
Jul 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.