Wednesday, September 9, 2026

Troop 61786’s Evolving C2 Footprint: Standalone Nodes, ASN 749 Targeting, and Academic Exploits

The operators behind PLA Troop 61786 (APT5) are at it again, attempting to sustain their cyber-espionage operations while continuing to exhibit sloppy tradecraft and persistent operational security failures. In my ongoing monitoring of their infrastructure, I have tracked significant shifts in their command-and-control (C2) setup, transit routing, and victim targeting over the final weeks of August. Below is a breakdown of our latest findings, standalone C2 observations, and actionable mitigations for network defenders.

Tuesday, September 1, 2026

Sloppy Routing and Regional Shifts: Troop 61786’s Late August Infrastructure Blitz

 


The "pro" hackers at Troop 61786 (APT5) are back at it under Wang's supervision, but their underlying tradecraft is still a complete disaster. No matter how many times they shift their infrastructure to dodge public exposure, their core habits and sloppy OPSEC remain as trackable as ever. If you are defending an enterprise network, you need to update your blocklists immediately. Here is a breakdown of the my analysis and brand-new indicators I uncovered from their late August campaign:

1. The QTRouter Botnet & Brazilian Staging Assets
In a new tactical development, I have discovered that Troop 61786 is deploying the QTRouter platform in addition to their usual JDY Botnet. Throughout August, they actively routed malicious operations through a cluster of Brazil-based IPs spanning the range of 45.205.1.240 to 45.205.1.247.
When hunting for this new QTRouter activity, security teams should closely monitor outbound connections on their favorite ports:
  • Standard/Evasive Ports: 443, 4443
  • Non-Standard High Ports: 1024, 3389, 20000, 40000, and 6000


2. Hiding Behind Russian Allies (The GRE False Flag)
My latest network analysis reveals a sneaky routing tactic designed to obscure their footprints and shift geopolitical blame. Troop 61786 is actively leveraging GRE (Generic Routing Encapsulation) protocols to tunnel traffic directly from their known domestic source ranges—106.38.113.0/24 and 106.120.218.0/24—through a single Russian IP: 45.12.124.70.
 
By routing through this Russian host, they are setting up their own allies to take the fall for their espionage campaigns. Auditing egress logs for unauthorized GRE tunnels connected to this host is highly recommended.

3. Regional Expansion: Bangladesh Staging
The group's operational infrastructure is expanding further into South Asia. Technical analysis confirms they have established active intrusion infrastructure hosted by a Bangladeshi internet service provider, One Net Communication. Add these newly identified Bangladeshi host IPs to your edge firewalls immediately:
  • 103.77.253.105
  • 103.77.253.106
  • 103.91.131.253

4. August Target Sweep: South Africa and Russia
While they were using Russian servers to hide their outbound traffic, they were simultaneously targeting Russian networks. Throughout August, Troop 61786 launched targeted network attacks originating from their primary source ranges (106.38.113.0/24 and 106.120.218.0/24) over secure port 443. This wave of scanning and exploitation specifically targeted two high-profile international nodes:
  • South African IP: 169.239.217.60
  • Russian IP: 185.50.202.190
These hosts are either active victims of the group's data-harvesting efforts or are being actively compromised to be recycled as future transit hops.

Defensive Actions Required
Updating blocklists is no longer optional. Ensure your network monitoring tools are flagging:
  1. Any traffic to the Brazilian QTRouter block (45.205.1.240-247) across ports 1024, 3389, 4443, 20000, 40000, or 60001.
  2. Any GRE tunnel handshakes associated with Russian IP 45.12.124.70.
  3. Active traffic to or from the One Net Communication host IPs in Bangladesh.
They can change their IPs, switch up their ports, and hide behind allies, but their amateurish footprint remains completely visible

Monday, August 24, 2026

August Resurgence: Troop 61786’s "Bring Your Botnet to Work" Campaign and Geopolitical Double-Crossing

 



Troop 61786 is back, and they definitely didn't bring their best.

After taking a brief break from their "custom" hosting setups in early August, the group has resurfaced with a spectacular lack of network sophistication. My latest research shows that they have abandoned even the illusion of stealth, adopting a messy "bring a botnet to work" covert infrastructure style.

If you are a network defender, update your blocklists immediately. Here is the technical breakdown of their new infrastructure, global targeting patterns, and the laws they are breaking along the way.

The Sloppy Botnet Infrastructure - Instead of their typical targeted staging blocks, the group has leaned heavily on a disorganized proxy setup. We have identified them relying on two core IPs for active operations:

    151.115.14.229
    57.128.166.86

Additionally, they appear to be routing active infrastructure traffic through:

    185.157.221.247
    45.205.1.243

The network is so poorly constructed and noisy that it looks like they asked a primary school class to build it. As always, their lack of basic operational hygiene remains their greatest vulnerability.                        

Global Government Targeting -
Despite the sloppy infrastructure, their mission objectives remain highly ambitious. Throughout the month of August, Troop 61786 has maintained a persistent campaign targeting government entities globally.
 

These scans and exploitation attempts are originating from a single primary IP:

    114.244.130.16

Confirmed targets in this August wave include the United States, Portuguese, and Italian governments, among several others. 

No Trust in Cyberspace: Hacking Their Own Allies - 
In the world of cyber-espionage, geopolitical alliances are entirely superficial. My latest analysis reveals that Troop 61786 spent the month of August conducting a highly concerted effort to compromise networks belonging to Russia—China’s own ally. The campaigns against Russian networks specifically targeted the following host IPs:

    46.17.45.230
    79.133.168.9 and 79.133.168.21
    94.19120.147 and 188.242.23.92

This serves as a clear reminder that no network is safe from their collection requirements, regardless of diplomatic ties.

Bypassing the Great Firewall via "Shadowsucks" - 
Ordinary Chinese citizens face strict legal penalties for attempting to bypass the Great Firewall, but Troop 61786 operates completely above domestic law. Our analysis shows the group is actively bypassing network controls from their own originating source ranges—including 106.38.113.0/24—using custom, homegrown "Shadowsucks" tunnels. We have successfully mapped this custom residential proxy network to the following entities:

    ASN 137897 (officially registered to Pan-Lian Technology, Co.)
    An IP scope falling precisely within 82.38.46.13 through 82.38.46.85, located in Hong Kong

Recommendations for Defenders:
They can shift their IPs, change their ports, and hide behind botnets, but their underlying habits and poor tradecraft remain completely visible. Update your firewalls to block the active infrastructure ranges listed above, audit egress traffic for "Shadowsucks" proxy signatures, and keep a close eye on unusual activity targeting public-sector interfaces.


You can run, but you can't hide.
For real-time indicator updates, follow me on X (https://x.com/calewnfd)

Tuesday, August 18, 2026

Threat Advisory: Operational Security Failures in Troop 61786 Infrastructure Transitions

 

1. Executive Summary

This advisory details recent shifts in the infrastructure and tactical methodology of the threat actor designated as Troop 61786 (also tracked as APT5). While the group has notably scaled back the volume of its primary campaigns, they maintain a persistent, albeit diminished, operational tempo that warrants continued scrutiny. In the discipline of cyber threat intelligence (CTI), periods of apparent de-escalation frequently signal retooling phases; observing actor behavior during these transitions is critical for maintaining a longitudinal understanding of their capabilities and identifying vulnerabilities in their operational model before they return to high-intensity activity.Current intelligence reveals a significant paradox in the group’s recent conduct: despite a reduced operational footprint, Troop 61786 is actively compromising its own anonymity through "sloppy OPSEC." While attempting to stand up and test new botnet infrastructure, the group failed to maintain logical separation between its originating environments. This lack of discipline has resulted in the exposure of three distinct source IP ranges, providing defenders with a high-fidelity targeting map of their current staging assets. By failing to isolate these environments, Troop 61786 has effectively de-anonymized its activity, allowing analysts to link disparate network segments to a single, coordinated campaign. The following technical assessment details how these infrastructure shifts provide a strategic opportunity to collapse the actor's operational tiers through network-level mapping.

2. Infrastructure and Activity Analysis

In CTI, infrastructure mapping serves as the foundation for proactive defense. By meticulously analyzing "source-to-target" patterns—the telemetry between an actor’s originating ranges and their staging or command-and-control (C2) assets—analysts can expose the underlying architecture of a botnet. When an actor fails to diversify their connection paths, they provide the "connective tissue" necessary for defenders to map the full extent of their reach.A critical operational failure was observed when Troop 61786 utilized three separate source ranges to interact simultaneously with a centralized target botnet. This cross-range correlation is an amateur error that facilitates the immediate identification of the actor's broader network footprint. The target infrastructure is comprised of three specific IP addresses:  45.201.1.242 45.205.1.243 , and  45.205.1.244 . These assets are hosted by  VPSVault  in  Brazil .The "so-what" of this activity lies in the total collapse of operational compartmentalization. By hitting the exact same VPSVault targets from all three source ranges, Troop 61786 has "cross-contaminated" its infrastructure. In a mature operational model, a compromise of one source IP should not lead to the discovery of others; however, these shared target IPs now function as a definitive pivot point. If a defender identifies traffic from any single source node, they can pivot to the VPSVault targets and subsequently identify every other range in the actor’s inventory. This strategic error effectively negates the group's attempts at redundancy and provides a high-confidence link between seemingly unrelated IP blocks. The subsequent technical indicators facilitate the translation of this analysis into actionable defensive controls and rigorous network monitoring.

3. Network Indicator Reference (IoCs)

The strategic role of Indicators of Compromise (IoCs) extends beyond simple blocking; they are the primary mechanism for proactive threat hunting. Blacklisting known malicious source infrastructure is essential for preventing initial access and identifying the actor's footprint within organizational telemetry.

Target Botnet Infrastructure

The following IPs constitute the destination infrastructure currently being staged or utilized by Troop 61786.| Target Botnet IP | Provider / Location || ------ | ------ || 45.201.1.242 | VPSVault / Brazil || 45.205.1.243 | VPSVault / Brazil || 45.205.1.244 | VPSVault / Brazil |

Source Infrastructure Breakdown

The following originating IPs have been identified as controlled by Troop 61786. To satisfy the technical observation of "three ranges," these IPs have been categorized by their respective subnet clusters.

           Source Range 1: 106.120.218.x

  • 106.120.218.147

  • 106.120.218.152

  • 106.120.218.181

  • 106.120.218.60

  • 106.120.218.34

  • 106.120.218.233

  • 106.120.218.179

  • 106.120.218.11

     Source Range 2: Subnet Cluster A

  • 218.30.23.11

  • 114.244.130.16

  • 221.216.117.22

     Source Range 3: Subnet Cluster B

  • 123.181.192.51

  • 124.64.23.2

Defensive Utility Analysis

These indicators should be integrated into Security Information and Event Management (SIEM) systems and perimeter defenses to trigger high-severity alerts. Specific detection logic should be implemented to identify multi-source ingress from these blocks toward shared internal assets or the known VPSVault targets. Because the actor's OPSEC failures have fundamentally linked these ranges, any observed activity from these IPs provides a high-confidence signal of a coordinated Troop 61786 operation. Organizations should prioritize egress filtering to the VPSVault IPs and ingress monitoring of the three identified source ranges.While Troop 61786 has scaled back the volume of its activity, the persistent evolution of their infrastructure requires vigilant monitoring to ensure that any resurgence in operational scale is met with an informed and robust defense.



Thursday, August 6, 2026

The Wandering Identity – Troop 61786’s habits outlast their infrastructure

The "pro" hackers at Troop 61786 are back at it under Wang's supervision, but their OPSEC is still a disaster. These operators are still likely playing video games directly from their C2 infrastructure and logging into their official PLA accounts from victim networks. 🎮💻 If you're defending a network, you need to watch for these specific indicators NOW:

  • Active Targeting: 221.216.117.22 over port 4501.

  • Infrastructure Lead: Connections to Blue Tech Technologies via 216.180.229.4 (port 999).

  • New Infrastructure Block (port 5995):

    • 57.128.28.86, 51.15.238.80, 51.159.97.251

    • 51.159.136.27, 57.128.29.136, 94.237.65.52

    • 94.237.75.228, 212.47.234.168

When your adversaries are this loud, use it to your advantage.


Monday, August 3, 2026

Troop 61786’s Return: New IPs, Same Old Tactics

Troop 61786 has resurfaced, with activity emanating from the 106.38.113.0/24 and 106.120.218.0/24 source ranges as they attempt to conceal their identities. Alongside these known ranges, there has been a recent surge in activity from new IP addresses, specifically 124.64.23.2 and 221.216.117.22, which have been observed communicating with ASN 749.
 
These actors are actively scanning and probing for vulnerabilities using their standard ports—80, 443, and 0 (ICMP)—while also utilizing more unusual ports such as 7000 and 8567. Their targeting remains focused on the defence, telecommunications, and technology sectors, but the scope of their operations also includes education and government organizations
 

 


Tuesday, July 28, 2026

More investigations into Troop 61786

 Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associated with APT5— I intend to provide periodic updates as I continue to track their activities. I wanted to share some more observations regarding their evolving tactics and hope to share more detailed findings soon as my investigation progresses.

Troop 61786 continues to exhibit sloppy tradecraft and poor OPSEC despite their desperate attempts to shift between infrastructure services to hide their tracks. While they have utilized the JDY Botnet and specific IP addresses like 181.189.10.216 and 45.154.159.12 to conceal their movements, their underlying lack of skill remains evident. Their amateurish security practices have likely  compromise the operations of more refined PRC actors, such as Volt Typhoon, who often target the same networks. A major operational failure occurred in March 2026 when the group attacked Telekomunikasi Indonesia (PT); during this engagement, they likely left significant amounts of personal data across the victim's network.

The group's global targeting remains wide but messy, impacting utility providers in the United States as well as the education sectors in Chile and Indonesia. To facilitate these operations, they rely on several VPS providers, including Contabo Gmbh, Hetzner, Beijing Volcano Engine Technology, Techoff Srv Limited, and Ucloud Information Technology. Despite using protocols such as TCP, ICMP, UDP, and GRE, their technical footprint is easily tracked due to recurring mistakes. Ultimately, their reliance on the JDY Botnet has failed to provide the professional cover they seek, leaving their infrastructure and lateral movements visible to investigators.



Troop 61786’s Evolving C2 Footprint: Standalone Nodes, ASN 749 Targeting, and Academic Exploits

The operators behind PLA Troop 61786 (APT5) are at it again, attempting to sustain their cyber-espionage operations while continuing to e...