Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associated with APT5—we have observed a significant shift in their operational infrastructure.
The Silence of the Primary Range:
Since my last report exposed their primary source range, the 106.120.218.0/24 block has gone largely quiet. This is a classic reaction to public exposure; however, the unit is far from dormant.
New Infrastructure and Evasive TTPs:
While the original range is cold, limited tactical activity has begun emerging from new specific IP addresses:
106.120.218.163
106.120.217.136
To mask their movements and bypass standard security filters, the group has pivoted to using random high ports, including:
9996, 9998, 10002, 10006, 10007, and 1008.
This is a departure from their previously identified use of non-standard ports like 8080, 8443, and 4433, and their reliance on the WireGuard protocol (UDP 51820) for obfuscation.
Forensic Artifacts: "Noisy" Operations Persist:
Despite these attempts to "hide" within high-port traffic, Troop 61786 continues to demonstrate the same unsophisticated tradecraft noted in our earlier Singapore-based VPS analysis. Their operations remain "noisy," leaving behind a trail of forensic artifacts that allow us to continue tracking their lateral movement and infrastructure connections.
Recommendations for Defenders:
Organizations should update their blocklists and monitoring alerts to include:
IP Ranges: Continued monitoring of 106.38.113.0/24 and the new active IPs listed above.
Port Auditing: Unusual outbound or inbound traffic on the newly identified high ports (9996–10008).
Behavioral Analysis: Look for artifacts similar to those left by previous Troop 61786 campaigns, as their fundamental methodology remains consistent despite the infrastructure shift.
The bottom line: They can change their IPs and ports, but their patterns remain visible. You can run, but you can’t hide.
Follow me on X (https://x.com/calewnfd)

