The operators behind PLA Troop 61786 (APT5) are at it again, attempting to sustain their cyber-espionage operations while continuing to exhibit sloppy tradecraft and persistent operational security failures. In my ongoing monitoring of their infrastructure, I have tracked significant shifts in their command-and-control (C2) setup, transit routing, and victim targeting over the final weeks of August. Below is a breakdown of our latest findings, standalone C2 observations, and actionable mitigations for network defenders.
1. C2 Infrastructure Exposure (Brazilian & German Nodes)
In their persistent attempts to maintain active C2 channels, Troop 61786 has diversified its hosting footprint across multiple international providers. I have observed operational infrastructure from both Brazilian and German infrastructure standing out as standalone components:
• Brazilian C2 Infrastructure: The group has stood up dedicated C2 nodes utilizing Brazilian IP addresses 172.237.61.190 and 172.237.61.194.
• German C2 Interactions: The group is actively maintaining outbound communications with German IP addresses 80.158.18.121, 80.158.20.148, and 80.158.38.48 over encrypted Port 443.
2. Sloppy ASN Targeting & Transit Routing
This infrastructure alignment connects directly to traffic patterns observed over the last three weeks of August. Troop 61786 directed a wave of scans and exploits at US-based targets located within ASN 749. Throughout this campaign, I recorded frequent, repeated outbound connections to IP space tied to Blue Tech Technologies. This pattern heavily indicates that the group is routing operational traffic through Blue Tech Technologies as a preferred transit provider to obfuscate their true origin.
3. Victimology & Academic Sector Focus
Despite attempts to hide behind new hosting providers and encrypted protocols, Troop 61786's tradecraft remains easily traceable. Their global targeting profile continues to hit educational and academic institutions:
• US Higher Education Targeting: In August, the group secured a short-lived compromise against a US university over Port 443.
• Impact: While the unit continues to probe critical sectors, their reliance on noisy, unrefined scanning scripts often exposes their infrastructure before deeper lateral movement can be sustained.
4. Action Checklist for Network Defenders
To protect enterprise perimeters and disrupt active Troop 61786 operations, security teams and SOC analysts should immediately implement the following defenses: 1. Update Firmware: Ensure all edge network appliances and firewall firmware are fully patched to eliminate public CVE vector entry points. 2. Block Origin Source Ranges: Actively block and monitor the Troop 61786 origin source subnet 114.244.130.0/24. 3. Audit Port 443 Traffic: Meticulously inspect encrypted Port 443 traffic for anomalous outbound connections to the German IP cluster (80.158.18.121, 80.158.20.148, 80.158.38.48) and Brazilian nodes (172.237.61.190, 172.237.61.194)
Indicators of Compromise (IOC) Summary Table
| Type | Indicator / Subnet | Context / Description |
|---|---|---|
| Brazilian C2 Nodes | 172.237.61.190172.237.61.194 |
Standalone C2 Infrastructure |
| German C2 Nodes | 80.158.18.12180.158.20.14880.158.38.48 |
Active outbound C2 communications over Port 443 |
| Origin Subnet Range | 114.244.130.0/24 |
Primary source origin range (Block & Monitor) |
| Targeted ASNs & Hosting | ASN 749 (US Targets) Blue Tech Technologies |
Preferred transit & target routing infrastructure |
The Bottom Line: They can switch VPS providers and rotate IP blocks, but their sloppy operational habits always give them away. You can run, but you can't hide. Follow my investigations on X (@calewnfd) for real-time updates.

No comments:
Post a Comment