Also known as: CONFERENCE CASTLE, the newspaper said yesterd, tracked as, operations, APT1, APT2, APT10, APT12, Vixen Panda, APT18, APT19, APT30, Naikon, APT31, Violet Typhoon, the Wuhan Xiaoruizhi Science, APT41, Winnti Group, Barium, Dragonbridge, UNC1945, GhostEmperor, APT3, Ke3chang, APT17, APT20, Suckfly, Turbine Panda, Technology Company, Axiom, Storm 1376, CHROMIUM, SODIUM, FamousSparrow, UNC6384
Conference Crew, now renamed CONFERENCE CASTLE under Google Cloud’s updated threat actor nomenclature, is a China‑nexus espionage group with long‑standing ties to the Chinese state apparatus. The organization targets a broad spectrum of sectors—including government, defense, aerospace, telecommunications, financial services, media, and critical infrastructure—across numerous countries spanning North America, Europe, Asia, and the Middle East. Operational analysis shows that Conference Crew typically employs large‑scale industrial‑themed phishing emails laden with malicious attachments or links. The malware delivered in these campaigns ranges from fully functional backdoors capable of credential theft to more focused utilities for data exfiltration. Several samples exhibit audio/video capture functionality, suggesting an emphasis on reconnaissance beyond digital footprints. The threat cluster combines opportunistic tactics—such as reply‑hijacking email chains—to expand reach with more sophisticated, coordinated campaigns that leverage custom obfuscation (cryppers/packers) to evade detection. While not every operation has been publicly attributed, indications point to a consistent pattern of using well‑crafted phishing narratives and resilient command‑and‑control infrastructures. The combination of wide sector coverage, advanced delivery mechanisms, and persistent state backing positions Conference Crew as a notable actor in the current cyberespionage landscape.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Conference Crew (also referred to as CONFERENCE CASTLE) is a China‑backed espionage cluster that uses industrial‑themed spearphishing campaigns to deliver custom backdoors and remote access tools to high‑value targets worldwide. Their operations focus on government, defense, critical infrastructure, and commercial sectors, seeking strategic intelligence and technology gains.
Goals & Targeting
Conference Crew’s primary objective is strategic espionage—collecting sensitive information from political, military, industrial, and scientific entities that could provide China with a competitive or security advantage. By targeting government departments, defense contractors, and critical infrastructure operators, they aim to acquire proprietary technology, policy insights, and geopolitical data. Their cross‑regional reach reflects an intent to gather intelligence not only for domestic use but also to support allied Chinese businesses seeking intellectual property theft. Typical victims are large enterprises with complex IT/OT environments, government agencies that house classified or strategic assets, and multinational corporations operating in sensitive sectors.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Conference Crew’s operations demonstrate a dual approach: mass opportunistic phishing with generic attachments combined with more organized, well‑crafted campaigns targeting specific industrial sectors. Analysts have noted that while much of the email traffic appears automated and low in polish, dedicated clusters employ realistic narratives and reply‑hijacking to infiltrate high‑profile targets. Although documented incidents lack a precise launch date, historical attribution links Conference Crew to earlier APT families such as APT1, APT10, and APT41. The group’s persistence lies in its ability to repurpose and refine malware frameworks over time, maintaining relevance across evolving enterprise defenses.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The profile of Conference Crew is derived primarily from a Wikipedia article, Google Cloud’s naming system update, and a Mandiant 2022 trend summary. While these sources confirm the actor’s existence, sector focus, and use of industrial‑themed phishing, specific evidence for many listed techniques or tools is inferred rather than directly cited. Detailed malware samples, precise operation timelines, and confirmed attribution to individual campaigns remain sparse, resulting in a moderate confidence level with gaps in operational specifics and tool validation.
No campaigns linked yet.
No observed data linked yet.
6
Techniques
44
Tools
0
Campaigns
40
IOCs
0
Observed Data
6
Tactics