Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Curious Gorge

Also known as: UNC3742

Description

Curious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in Ukraine, Russia, Kazakhstan, and Mongolia. The actor has remained active against government, military, logistics and manufacturing organizations in Ukraine, Russia and Central Asia. In Russia, long running campaigns against multiple government organizations have continued, including the Ministry of Foreign Affairs. Over the past week, TAG identified additional compromises impacting multiple Russian defense contractors and manufacturers and a Russian logistics company.

Goals & Targeting

Targeted Sectors

Government
Defense
Transportation

AI Analysis

· 1 week ago

Executive Summary

Curious Gorge (aka UNC3742), attributed to China's PLA SSF, targets government and defense sectors in Ukraine, Russia, Kazakhstan, and Mongolia. The group conducts prolonged campaigns focusing on情报 gathering and infrastructure compromise. While specifics like TTPs and tools remain unclear, their activity indicates a nation-state level of sophistication with significant operational reach.

Goals & Targeting

Curious Gorge's primary objectives appear to be intelligence collection and disruption of key infrastructure in target countries. Their focus on government and defense sectors suggests a desire to gather sensitive information and undermine national security capabilities. The actor's targeting strategy reflects a long-term commitment to specific regions, indicating operational patience and strategic planning.

Enhanced Description

Curious Gorge is a state-sponsored threat actor linked to China's People's Liberation Army (PLA) Strategic Support Force (SSF). The group has been actively targeting government, military, logistics, and defense organizations in Eastern Europe and Central Asia. Campaigns have included targeted compromises of Russian defense contractors, manufacturers, and logistics companies. Curious Gorge employs persistent cyber operations, often focusing on long-term access to maintain a foothold in victim networks. Despite limited public reporting on their specific tactics, indicators suggest they are highly sophisticated, likely utilizing custom malware and advanced persistence techniques. Their geographic focus on Russia, Ukraine, and Central Asian countries aligns with potential geopolitical interests, possibly aimed at gathering intel for strategic advantage.

Key Capabilities

  • State-sponsored cyber operations
  • Persistent network presence
  • Targeted compromise of critical infrastructure
  • Intelligence gathering on defense and government activities

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration

ATT&CK Techniques

T1078
T1569
T1214
T1055

Software / Tooling

Custom Malware
Common Tools (Inference)

Campaigns & Victims

Curious Gorge has demonstrated a sustained operational tempo, with campaigns spanning multiple years. Their focus on Russia and Ukraine suggests a regional strategy aimed at destabilization or intelligence collection targets. Notable operations include compromises of the Russian Ministry of Foreign Affairs and defense contractors in Ukraine.

IOC Patterns

  • Spear-phishing emails targeting government/military employees
  • Domain generation activity (likely C2)
  • Network traffic anomalies in government/defense networks
  • Artifacts in compromised systems aligning with APT activity

Recommended Actions

  • Implement robust email filtering to detect spear-phishing attempts.
  • Monitor network traffic for signs of C2 communication patterns.
  • Conduct regular audits of critical infrastructure for unauthorized access.
  • Adopt MFA (Multi-Factor Authentication) where possible.

Suggested Tags

APT
espionage
government-sector

Confidence Assessment

Low confidence due to limited public reporting on Curious Gorge. While their nation-state sponsorship and targeting patterns are inferred with moderate confidence, specific TTPs remain unknown. Data gaps include exact timelines of activity, specific tools used, and the full scope of their campaigns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Critical Infrastructure
Government Targeting
espionage
government-sector

Details

Type
Nation-State
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.