Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associated with APT5— I intend to provide periodic updates as I continue to track their activities. I wanted to share some more observations regarding their evolving tactics and hope to share more detailed findings soon as my investigation progresses.
Troop 61786 continues to exhibit sloppy tradecraft and poor OPSEC despite their desperate attempts to shift between infrastructure services to hide their tracks. While they have utilized the JDY Botnet and specific IP addresses like 181.189.10.216 and 45.154.159.12 to conceal their movements, their underlying lack of skill remains evident. Their amateurish security practices have likely compromise the operations of more refined PRC actors, such as Volt Typhoon, who often target the same networks. A major operational failure occurred in March 2026 when the group attacked Telekomunikasi Indonesia (PT); during this engagement, they likely left significant amounts of personal data across the victim's network.
The group's global targeting remains wide but messy, impacting utility providers in the United States as well as the education sectors in Chile and Indonesia. To facilitate these operations, they rely on several VPS providers, including Contabo Gmbh, Hetzner, Beijing Volcano Engine Technology, Techoff Srv Limited, and Ucloud Information Technology. Despite using protocols such as TCP, ICMP, UDP, and GRE, their technical footprint is easily tracked due to recurring mistakes. Ultimately, their reliance on the JDY Botnet has failed to provide the professional cover they seek, leaving their infrastructure and lateral movements visible to investigators.
Tuesday, July 28, 2026
More investigations into Troop 61786
Friday, July 3, 2026
Update: Tactical Shifts and New Indicators for Troop 61786 (APT5)
Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associated with APT5—we have observed a significant shift in their operational infrastructure.
The Silence of the Primary Range:
Since my last report exposed their primary source range, the 106.120.218.0/24 block has gone largely quiet. This is a classic reaction to public exposure; however, the unit is far from dormant.
New Infrastructure and Evasive TTPs:
While the original range is cold, limited tactical activity has begun emerging from new specific IP addresses:
106.120.218.163
106.120.217.136
To mask their movements and bypass standard security filters, the group has pivoted to using random high ports, including:
9996, 9998, 10002, 10006, 10007, and 1008.
This is a departure from their previously identified use of non-standard ports like 8080, 8443, and 4433, and their reliance on the WireGuard protocol (UDP 51820) for obfuscation.
Forensic Artifacts: "Noisy" Operations Persist:
Despite these attempts to "hide" within high-port traffic, Troop 61786 continues to demonstrate the same unsophisticated tradecraft noted in our earlier Singapore-based VPS analysis. Their operations remain "noisy," leaving behind a trail of forensic artifacts that allow us to continue tracking their lateral movement and infrastructure connections.
Recommendations for Defenders:
Organizations should update their blocklists and monitoring alerts to include:
IP Ranges: Continued monitoring of 106.38.113.0/24 and the new active IPs listed above.
Port Auditing: Unusual outbound or inbound traffic on the newly identified high ports (9996–10008).
Behavioral Analysis: Look for artifacts similar to those left by previous Troop 61786 campaigns, as their fundamental methodology remains consistent despite the infrastructure shift.
The bottom line: They can change their IPs and ports, but their patterns remain visible. You can run, but you can’t hide.
Follow me on X (https://x.com/calewnfd)
Troop 61786’s Evolving C2 Footprint: Standalone Nodes, ASN 749 Targeting, and Academic Exploits
The operators behind PLA Troop 61786 (APT5) are at it again, attempting to sustain their cyber-espionage operations while continuing to e...
-
I am relatively new to the cybersecurity community and I have tracked low-level, criminal groups who conduct computer network exploitation ...
-
Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associate...
-
Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associated w...


