Also known as: Golden Falcon
APT‑C‑34 was first uncovered by Chinese cyber‑security vendor Qihoo 360 in a report released on 29 November 2019. The analysis revealed an extensive operation directed at Kazakhstan that involved widespread infiltration of individuals and organizations across virtually every sector, from the highest levels of government and the military to religious leaders and ordinary citizens. According to Qihoo, the attackers deployed a combination of custom‑developed malware, commercially available surveillance spyware, and expensive radio‑interception hardware—an arsenal that indicates significant resources at their disposal. The campaign’s breadth suggests an information‑intelligence focus: by accessing sensitive communications in diplomatic circles, monitoring dissenting voices, and tracking research initiatives, the actor could shape narratives or anticipate policy moves. The use of both bespoke tools and off‑the‑shelf spyware points to a hybrid approach that balances stealth, flexibility, and power. Despite the limited public disclosure, the Qihoo investigation implies that APT‑C‑34 is capable of long‑term operations with multiple delivery vectors, advanced lateral movement capabilities, and a clear strategic agenda.
Executive Summary
APT‑C‑34, also known as Golden Falcon, is a highly resourceful threat actor that emerged in late 2019 with an expansive hacking campaign against Kazakhstan. The group targeted a wide range of entities—including government agencies, military personnel, diplomats, journalists, researchers, private firms, educational institutions, religious figures and dissidents—using advanced tools that suggest possible state backing. While detailed technical attribution is limited, the evidence points to a sophisticated actor pursuing political or intelligence objectives rather than financial gain.
Goals & Targeting
APT‑C‑34 concentrates on entities that provide political, strategic, or informational leverage within Kazakhstan. Target selection spans government, military, diplomatic, academic, journalistic, private sector, religious, and civil society nodes—groups whose data can inform foreign policy decisions, monitor opposition activity, or expose state secrets. The actor’s broad reach indicates an intelligence‑gathering motive, with the potential to influence outcomes in both domestic and regional affairs rather than focusing on monetary exploitation.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The APT‑C‑34 campaign first surfaced in November 2019 and has operated predominantly against entities in Kazakhstan. Evidence from Qihoo points to a sustained effort that combines bespoke malware with commercial spyware, leveraging multiple delivery methods—including spear‑phishing emails, malicious attachments, possibly radio‑signal hijacking—and targeting high‑profile officials as well as ordinary citizens. Victims range from political leaders and military personnel to journalists and researchers, suggesting an opportunistic approach aimed at maximizing intelligence gains rather than extracting financial value. While detailed logs are sparse, the operational breadth implies a long‑term, resource‑heavy program aligned with state interests.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available information primarily stems from a single Qihoo 360 report released via ZDNet in November 2019. While the targeting profile and resource indicators are reasonably supported, details regarding specific TTPs, operational tempo, and recent activity remain largely unverified. Consequently, confidence is moderate for strategic intent and broad sector coverage but low for technical attribution, tool usage, and current engagement status.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
5
Tools
0
Campaigns
1
IOCs
0
Observed Data
6
Tactics