Tuesday, July 28, 2026

More investigations into Troop 61786

 Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associated with APT5— I intend to provide periodic updates as I continue to track their activities. I wanted to share some more observations regarding their evolving tactics and hope to share more detailed findings soon as my investigation progresses.

Troop 61786 continues to exhibit sloppy tradecraft and poor OPSEC despite their desperate attempts to shift between infrastructure services to hide their tracks. While they have utilized the JDY Botnet and specific IP addresses like 181.189.10.216 and 45.154.159.12 to conceal their movements, their underlying lack of skill remains evident. Their amateurish security practices have likely  compromise the operations of more refined PRC actors, such as Volt Typhoon, who often target the same networks. A major operational failure occurred in March 2026 when the group attacked Telekomunikasi Indonesia (PT); during this engagement, they likely left significant amounts of personal data across the victim's network.

The group's global targeting remains wide but messy, impacting utility providers in the United States as well as the education sectors in Chile and Indonesia. To facilitate these operations, they rely on several VPS providers, including Contabo Gmbh, Hetzner, Beijing Volcano Engine Technology, Techoff Srv Limited, and Ucloud Information Technology. Despite using protocols such as TCP, ICMP, UDP, and GRE, their technical footprint is easily tracked due to recurring mistakes. Ultimately, their reliance on the JDY Botnet has failed to provide the professional cover they seek, leaving their infrastructure and lateral movements visible to investigators.



No comments:

Post a Comment

More investigations into Troop 61786

 Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associated w...