Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Conference Crew

Also known as: CONFERENCE CASTLE, the newspaper said yesterd, tracked as, operations, APT1, APT2, APT10, APT12, Vixen Panda, APT18, APT19, APT30, Naikon, APT31, Violet Typhoon, the Wuhan Xiaoruizhi Science, APT41, Winnti Group, Barium, Dragonbridge, UNC1945, GhostEmperor, APT3, Ke3chang, APT17, APT20, Suckfly, Turbine Panda, Technology Company, Axiom, Storm 1376, CHROMIUM, SODIUM, FamousSparrow, UNC6384

Description

Conference Crew, now renamed CONFERENCE CASTLE under Google Cloud’s updated threat actor nomenclature, is a China‑nexus espionage group with long‑standing ties to the Chinese state apparatus. The organization targets a broad spectrum of sectors—including government, defense, aerospace, telecommunications, financial services, media, and critical infrastructure—across numerous countries spanning North America, Europe, Asia, and the Middle East. Operational analysis shows that Conference Crew typically employs large‑scale industrial‑themed phishing emails laden with malicious attachments or links. The malware delivered in these campaigns ranges from fully functional backdoors capable of credential theft to more focused utilities for data exfiltration. Several samples exhibit audio/video capture functionality, suggesting an emphasis on reconnaissance beyond digital footprints. The threat cluster combines opportunistic tactics—such as reply‑hijacking email chains—to expand reach with more sophisticated, coordinated campaigns that leverage custom obfuscation (cryppers/packers) to evade detection. While not every operation has been publicly attributed, indications point to a consistent pattern of using well‑crafted phishing narratives and resilient command‑and‑control infrastructures. The combination of wide sector coverage, advanced delivery mechanisms, and persistent state backing positions Conference Crew as a notable actor in the current cyberespionage landscape.

Goals & Targeting

Targeted Sectors

Government
Defense
Education
Media
Telecommunications
Financial services
Non profit
Aerospace
Healthcare
Manufacturing
Aviation
Critical infrastructure
Hospitality
Energy
Utilities
Construction
Food agriculture
Gaming
Information technology
Nuclear

Targeted Countries / Regions

CN
US
IN
TW
JP
GB
SG
RU
VN
DE
FR
AU
NL
PL
CA
KZ
KR
TR

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

Conference Crew (also referred to as CONFERENCE CASTLE) is a China‑backed espionage cluster that uses industrial‑themed spearphishing campaigns to deliver custom backdoors and remote access tools to high‑value targets worldwide. Their operations focus on government, defense, critical infrastructure, and commercial sectors, seeking strategic intelligence and technology gains.

Goals & Targeting

Conference Crew’s primary objective is strategic espionage—collecting sensitive information from political, military, industrial, and scientific entities that could provide China with a competitive or security advantage. By targeting government departments, defense contractors, and critical infrastructure operators, they aim to acquire proprietary technology, policy insights, and geopolitical data. Their cross‑regional reach reflects an intent to gather intelligence not only for domestic use but also to support allied Chinese businesses seeking intellectual property theft. Typical victims are large enterprises with complex IT/OT environments, government agencies that house classified or strategic assets, and multinational corporations operating in sensitive sectors.

Enhanced Description

Key Capabilities

  • Spearphishing emails featuring industrial‑themed narratives
  • Delivery of customized backdoors capable of credential harvesting and remote access
  • Use of crypters/packers to obfuscate payloads and evade detection
  • Embedded audio/video capture modules within RATs
  • Email reply hijacking to scale campaigns rapidly

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Command & Control
Exfiltration

ATT&CK Techniques

T1566.001
T1003.001
T1059.004
T1114.002
T1071.003
T1520

Software / Tooling

Custom RATs (generic)
Mimikatz
PowerShell scripts
Crypters/Packers such as UPX

Campaigns & Victims

Conference Crew’s operations demonstrate a dual approach: mass opportunistic phishing with generic attachments combined with more organized, well‑crafted campaigns targeting specific industrial sectors. Analysts have noted that while much of the email traffic appears automated and low in polish, dedicated clusters employ realistic narratives and reply‑hijacking to infiltrate high‑profile targets. Although documented incidents lack a precise launch date, historical attribution links Conference Crew to earlier APT families such as APT1, APT10, and APT41. The group’s persistence lies in its ability to repurpose and refine malware frameworks over time, maintaining relevance across evolving enterprise defenses.

IOC Patterns

  • Industrial‑theme spearphishing emails with malicious attachments or download links
  • Custom backdoor payloads delivered via HTTP/HTTPS streams
  • Obfuscated executables using crypters or packers
  • Reply hijacking technique to hijack legitimate email chains
  • Potential use of DNS tunneling for covert C2 (not confirmed)

Recommended Actions

  • Implement mandatory email attachment sandboxing and advanced phishing detection rules that flag industrial‑themed content
  • Educate employees on recognizing spoofed OT or engineering emails and enforce strict verification protocols
  • Enforce principle of least privilege and multi‑factor authentication across all critical systems
  • Deploy next‑generation endpoint detection and response to spot abnormal credential dumping or remote access tools
  • Block outbound traffic to known bad IPs and monitor for unusual DNS queries that may indicate tunneling
  • Regularly update and patch systems, especially OT components, to close exploitable vulnerabilities
  • Conduct periodic threat hunting focused on the tactics identified in the MITRE ATT&CK matrix

Suggested Tags

APT
espionage
China-based
industrial espionage
government
defense
critical infrastructure
phishing
RAT

Confidence Assessment

The profile of Conference Crew is derived primarily from a Wikipedia article, Google Cloud’s naming system update, and a Mandiant 2022 trend summary. While these sources confirm the actor’s existence, sector focus, and use of industrial‑themed phishing, specific evidence for many listed techniques or tools is inferred rather than directly cited. Detailed malware samples, precise operation timelines, and confirmed attribution to individual campaigns remain sparse, resulting in a moderate confidence level with gaps in operational specifics and tool validation.

ATT&CK Techniques

Command & Control
1 technique
Credential Access
1 technique
Execution
1 technique
Initial Access
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. en.wikipedia.org — Cited by web research for: the newspaper said yesterd
  2. cloud.google.com — Cited by web research for: operations
  3. cloud.google.com — Cited by web research for: Hermit
  4. https://www.mandiant.com/resources/m-trends-2022 — Cited by AI analysis.
  5. ko.wikipedia.org — Cited by web research for: www.justice.gov

Intel Summary

6

Techniques

44

Tools

0

Campaigns

40

IOCs

0

Observed Data

6

Tactics

Tags

APT
espionage
China-based
industrial espionage
government
defense
critical infrastructure
phishing
RAT

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.