The "pro" hackers at Troop 61786 (APT5) are back at it under Wang's supervision, but their underlying tradecraft is still a complete disaster. No matter how many times they shift their infrastructure to dodge public exposure, their core habits and sloppy OPSEC remain as trackable as ever. If you are defending an enterprise network, you need to update your blocklists immediately. Here is a breakdown of the my analysis and brand-new indicators I uncovered from their late August campaign:
1. The QTRouter Botnet & Brazilian Staging Assets
In a new tactical development, I have discovered that Troop 61786 is deploying the QTRouter platform in addition to their usual JDY Botnet. Throughout August, they actively routed malicious operations through a cluster of Brazil-based IPs spanning the range of 45.205.1.240 to 45.205.1.247.
When hunting for this new QTRouter activity, security teams should closely monitor outbound connections on their favorite ports:
- Standard/Evasive Ports:
443,4443 - Non-Standard High Ports:
1024,3389,20000,40000, and6000
2. Hiding Behind Russian Allies (The GRE False Flag)
My latest network analysis reveals a sneaky routing tactic designed to obscure their footprints and shift geopolitical blame. Troop 61786 is actively leveraging GRE (Generic Routing Encapsulation) protocols to tunnel traffic directly from their known domestic source ranges—106.38.113.0/24 and 106.120.218.0/24—through a single Russian IP: 45.12.124.70.
By routing through this Russian host, they are setting up their own allies to take the fall for their espionage campaigns. Auditing egress logs for unauthorized GRE tunnels connected to this host is highly recommended.
3. Regional Expansion: Bangladesh Staging
The group's operational infrastructure is expanding further into South Asia. Technical analysis confirms they have established active intrusion infrastructure hosted by a Bangladeshi internet service provider, One Net Communication. Add these newly identified Bangladeshi host IPs to your edge firewalls immediately:
- 103.77.253.105
- 103.77.253.106
- 103.91.131.253
4. August Target Sweep: South Africa and Russia
While they were using Russian servers to hide their outbound traffic, they were simultaneously targeting Russian networks. Throughout August, Troop 61786 launched targeted network attacks originating from their primary source ranges (106.38.113.0/24 and 106.120.218.0/24) over secure port
443. This wave of scanning and exploitation specifically targeted two high-profile international nodes:- South African IP:
169.239.217.60 - Russian IP:
185.50.202.190
These hosts are either active victims of the group's data-harvesting efforts or are being actively compromised to be recycled as future transit hops.
Defensive Actions Required
Updating blocklists is no longer optional. Ensure your network monitoring tools are flagging:
- Any traffic to the Brazilian QTRouter block (
45.205.1.240-247) across ports1024,3389,4443,20000,40000, or60001. - Any GRE tunnel handshakes associated with Russian IP 45.12.124.70.
- Active traffic to or from the One Net Communication host IPs in Bangladesh.
They can change their IPs, switch up their ports, and hide behind allies, but their amateurish footprint remains completely visible


No comments:
Post a Comment