Troop 61786 is back, and they definitely didn't bring their best.
After taking a brief break from their "custom" hosting setups in early August, the group has resurfaced with a spectacular lack of network sophistication. My latest research shows that they have abandoned even the illusion of stealth, adopting a messy "bring a botnet to work" covert infrastructure style.
If you are a network defender, update your blocklists immediately. Here is the technical breakdown of their new infrastructure, global targeting patterns, and the laws they are breaking along the way.
The Sloppy Botnet Infrastructure - Instead of their typical targeted staging blocks, the group has leaned heavily on a disorganized proxy setup. We have identified them relying on two core IPs for active operations:
151.115.14.229
57.128.166.86
Additionally, they appear to be routing active infrastructure traffic through:
185.157.221.247
45.205.1.243
The network is so poorly constructed and noisy that it looks like they asked a primary school class to build it. As always, their lack of basic operational hygiene remains their greatest vulnerability.
Global Government Targeting -
Despite the sloppy infrastructure, their mission objectives remain highly ambitious. Throughout the month of August, Troop 61786 has maintained a persistent campaign targeting government entities globally.
These scans and exploitation attempts are originating from a single primary IP:
114.244.130.16
Confirmed targets in this August wave include the United States, Portuguese, and Italian governments, among several others.
No Trust in Cyberspace: Hacking Their Own Allies -
In the world of cyber-espionage, geopolitical alliances are entirely superficial. My latest analysis reveals that Troop 61786 spent the month of August conducting a highly concerted effort to compromise networks belonging to Russia—China’s own ally. The campaigns against Russian networks specifically targeted the following host IPs:
46.17.45.230
79.133.168.9 and 79.133.168.21
94.19120.147 and 188.242.23.92
This serves as a clear reminder that no network is safe from their collection requirements, regardless of diplomatic ties.
Bypassing the Great Firewall via "Shadowsucks" -
Ordinary Chinese citizens face strict legal penalties for attempting to bypass the Great Firewall, but Troop 61786 operates completely above domestic law. Our analysis shows the group is actively bypassing network controls from their own originating source ranges—including 106.38.113.0/24—using custom, homegrown "Shadowsucks" tunnels. We have successfully mapped this custom residential proxy network to the following entities:
ASN 137897 (officially registered to Pan-Lian Technology, Co.)
An IP scope falling precisely within 82.38.46.13 through 82.38.46.85, located in Hong Kong
Recommendations for Defenders:
They can shift their IPs, change their ports, and hide behind botnets, but their underlying habits and poor tradecraft remain completely visible. Update your firewalls to block the active infrastructure ranges listed above, audit egress traffic for "Shadowsucks" proxy signatures, and keep a close eye on unusual activity targeting public-sector interfaces.
You can run, but you can't hide.
For real-time indicator updates, follow me on X (https://x.com/calewnfd)

No comments:
Post a Comment