Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TempTick

Description

This threat actor targets organizations in the finance, defense, aerospace, technology, health-care, and automotive sectors and media organizations in East Asia for the purpose of espionage. Believed to be responsible for the targeting of South Korean actors prior to the meeting of Donald J. Trump and Kim Jong-un

Goals & Targeting

Targeted Sectors

Government

AI Analysis

· 2 weeks ago

Executive Summary

TempTick is a suspected advanced persistent threat (APT) group targeting various sectors in East Asia for espionage purposes. Their activities are linked to political gatherings, suggesting state-sponsored motivations. They employ sophisticated tactics, including long-term campaigns, to infiltrate critical infrastructure and extract sensitive information.

Goals & Targeting

TempTick's objectives are centered around gathering intelligence through espionage. They specifically target sectors that hold strategic importance, likely to gain geopolitical advantages or support state interests, particularly in East Asia. Their targeting of South Korean entities prior to significant political events suggests a focus on influencing regional dynamics.

Enhanced Description

TempTick operates with precision, focusing on high-value sectors such as finance, defense, aerospace, technology, healthcare, automotive, and media in East Asia. Their primary objective appears to be espionage, targeting South Korean actors ahead of significant international meetings, which implies a possible state-actor background. The group is known for its strategic approach, employing persistent campaign techniques to infiltrate networks and exfiltrate sensitive data.

Key Capabilities

  • Sophisticated APT techniques
  • Long-term campaign persistence
  • Espionage activity
  • Targeted sector infiltration

MITRE ATT&CK Tactics

Initial Access
Collection
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom恶意软件
spear-phishing 工具
数据渗출工具

Campaigns & Victims

TempTick's campaigns are characterized by their longevity and focus on high-value targets. They often precede significant political events, indicating a strategic timing component. Their operations in East Asia suggest a regional focus aimed at gaining competitive intelligence advantages.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • C2 infrastructure using fast-flux domains
  • Network traffic anomalies during peak data exfiltration times

Recommended Actions

  • Implement multi-layered email security to detect phishing attempts
  • Monitor network traffic for unusual patterns and C2 communications
  • Segment sensitive networks to limit lateral movement
  • Conduct regular security audits and simulations targeting high-risk sectors

Suggested Tags

APT
espionage
East Asia
spear-phishing

Confidence Assessment

High confidence in TempTick's APT nature due to targeted, persistent campaigns. However, specific tools and exact origins remain unclear.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
East Asia
spear-phishing

Details

Type
Unknown
Country of Origin
C
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.