Also known as: NetTraveler, APT21, HAMMER PANDA, TEMP.Zhenbao
**Targets:** This threat actor targets computer networks associated with Tibetan and Uyghur activists for espionage purposes. **Toolset/Malware:** NetTraveler
Targeted Sectors
Targeted Countries / Regions
Executive Summary
NetTraveler is a state-sponsored advanced persistent threat (APT) group linked to Chinese espionage activities. The actor primarily targets government and defense sectors in Russia and focuses on gathering intelligence from individuals associated with Tibetan and Uyghur activists. NetTraveler's operations demonstrate moderate sophistication, utilizing custom malware for long-term network access and data exfiltration.
Goals & Targeting
NetTraveler's strategic objectives appear to revolve around gathering sensitive information and intelligence from government and defense sectors, likely to support national security interests. Their targeting of activists associated with the Tibetan and Uyghur communities suggests a focus on regions or individuals perceived as threats to Chinese stability. The actor's primary victims are individuals and organizations linked to these ethnic groups, as well as government entities that may have ties to them.
Enhanced Description
NetTraveler is a state-sponsored threat group known to target government and defense-related computer networks, primarily within Russia. The actor has been linked to espionage activities aimed at collecting sensitive information from individuals associated with Tibetan and Uyghur activism. While specific details about NetTraveler's tactics are limited, they are believed to employ custom malware for initial access, lateral movement, and data exfiltration. Their operations suggest a focus on maintaining persistence within targeted networks, indicative of long-term espionage goals. The group's activities underscore the broader threat of nation-state actors using cyber means to target specific ethnic or political groups for intelligence collection.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
NetTraveler's campaigns are characterized by targeted attacks against specific individuals and organizations. The actor likely uses spear-phishing emails or malicious links to gain initial access, followed by internal network movement and data collection. While no specific campaigns have been widely reported, the group's activities suggest a focus on长期潜伏和情报收集, aligning with state-sponsored espionage tactics.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in NetTraveler's details is moderate, as the group appears to be relatively obscure compared to other APTs like APT29 or APT31. Specific information about their tactics, techniques, and procedures (TTPs) remains limited, with much of the reporting focused on their targeting of activists rather than corporate or high-profile entities. Data gaps include their exact first and last observed activity dates, specific campaign details, and complete toolset.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
1
Tools
0
Campaigns
14
IOCs
0
Observed Data
0
Tactics