Also known as: UNC3742
Curious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in Ukraine, Russia, Kazakhstan, and Mongolia. The actor has remained active against government, military, logistics and manufacturing organizations in Ukraine, Russia and Central Asia. In Russia, long running campaigns against multiple government organizations have continued, including the Ministry of Foreign Affairs. Over the past week, TAG identified additional compromises impacting multiple Russian defense contractors and manufacturers and a Russian logistics company.
Targeted Sectors
Executive Summary
Curious Gorge (aka UNC3742), attributed to China's PLA SSF, targets government and defense sectors in Ukraine, Russia, Kazakhstan, and Mongolia. The group conducts prolonged campaigns focusing on情报 gathering and infrastructure compromise. While specifics like TTPs and tools remain unclear, their activity indicates a nation-state level of sophistication with significant operational reach.
Goals & Targeting
Curious Gorge's primary objectives appear to be intelligence collection and disruption of key infrastructure in target countries. Their focus on government and defense sectors suggests a desire to gather sensitive information and undermine national security capabilities. The actor's targeting strategy reflects a long-term commitment to specific regions, indicating operational patience and strategic planning.
Enhanced Description
Curious Gorge is a state-sponsored threat actor linked to China's People's Liberation Army (PLA) Strategic Support Force (SSF). The group has been actively targeting government, military, logistics, and defense organizations in Eastern Europe and Central Asia. Campaigns have included targeted compromises of Russian defense contractors, manufacturers, and logistics companies. Curious Gorge employs persistent cyber operations, often focusing on long-term access to maintain a foothold in victim networks. Despite limited public reporting on their specific tactics, indicators suggest they are highly sophisticated, likely utilizing custom malware and advanced persistence techniques. Their geographic focus on Russia, Ukraine, and Central Asian countries aligns with potential geopolitical interests, possibly aimed at gathering intel for strategic advantage.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Curious Gorge has demonstrated a sustained operational tempo, with campaigns spanning multiple years. Their focus on Russia and Ukraine suggests a regional strategy aimed at destabilization or intelligence collection targets. Notable operations include compromises of the Russian Ministry of Foreign Affairs and defense contractors in Ukraine.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence due to limited public reporting on Curious Gorge. While their nation-state sponsorship and targeting patterns are inferred with moderate confidence, specific TTPs remain unknown. Data gaps include exact timelines of activity, specific tools used, and the full scope of their campaigns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics