Monday, August 24, 2026

August Resurgence: Troop 61786’s "Bring Your Botnet to Work" Campaign and Geopolitical Double-Crossing

 



Troop 61786 is back, and they definitely didn't bring their best.

After taking a brief break from their "custom" hosting setups in early August, the group has resurfaced with a spectacular lack of network sophistication. My latest research shows that they have abandoned even the illusion of stealth, adopting a messy "bring a botnet to work" covert infrastructure style.

If you are a network defender, update your blocklists immediately. Here is the technical breakdown of their new infrastructure, global targeting patterns, and the laws they are breaking along the way.

The Sloppy Botnet Infrastructure - Instead of their typical targeted staging blocks, the group has leaned heavily on a disorganized proxy setup. We have identified them relying on two core IPs for active operations:

    151.115.14.229
    57.128.166.86

Additionally, they appear to be routing active infrastructure traffic through:

    185.157.221.247
    45.205.1.243

The network is so poorly constructed and noisy that it looks like they asked a primary school class to build it. As always, their lack of basic operational hygiene remains their greatest vulnerability.                        

Global Government Targeting -
Despite the sloppy infrastructure, their mission objectives remain highly ambitious. Throughout the month of August, Troop 61786 has maintained a persistent campaign targeting government entities globally.
 

These scans and exploitation attempts are originating from a single primary IP:

    114.244.130.16

Confirmed targets in this August wave include the United States, Portuguese, and Italian governments, among several others. 

No Trust in Cyberspace: Hacking Their Own Allies - 
In the world of cyber-espionage, geopolitical alliances are entirely superficial. My latest analysis reveals that Troop 61786 spent the month of August conducting a highly concerted effort to compromise networks belonging to Russia—China’s own ally. The campaigns against Russian networks specifically targeted the following host IPs:

    46.17.45.230
    79.133.168.9 and 79.133.168.21
    94.19120.147 and 188.242.23.92

This serves as a clear reminder that no network is safe from their collection requirements, regardless of diplomatic ties.

Bypassing the Great Firewall via "Shadowsucks" - 
Ordinary Chinese citizens face strict legal penalties for attempting to bypass the Great Firewall, but Troop 61786 operates completely above domestic law. Our analysis shows the group is actively bypassing network controls from their own originating source ranges—including 106.38.113.0/24—using custom, homegrown "Shadowsucks" tunnels. We have successfully mapped this custom residential proxy network to the following entities:

    ASN 137897 (officially registered to Pan-Lian Technology, Co.)
    An IP scope falling precisely within 82.38.46.13 through 82.38.46.85, located in Hong Kong

Recommendations for Defenders:
They can shift their IPs, change their ports, and hide behind botnets, but their underlying habits and poor tradecraft remain completely visible. Update your firewalls to block the active infrastructure ranges listed above, audit egress traffic for "Shadowsucks" proxy signatures, and keep a close eye on unusual activity targeting public-sector interfaces.


You can run, but you can't hide.
For real-time indicator updates, follow me on X (https://x.com/calewnfd)

Tuesday, August 18, 2026

Threat Advisory: Operational Security Failures in Troop 61786 Infrastructure Transitions

 

1. Executive Summary

This advisory details recent shifts in the infrastructure and tactical methodology of the threat actor designated as Troop 61786 (also tracked as APT5). While the group has notably scaled back the volume of its primary campaigns, they maintain a persistent, albeit diminished, operational tempo that warrants continued scrutiny. In the discipline of cyber threat intelligence (CTI), periods of apparent de-escalation frequently signal retooling phases; observing actor behavior during these transitions is critical for maintaining a longitudinal understanding of their capabilities and identifying vulnerabilities in their operational model before they return to high-intensity activity.Current intelligence reveals a significant paradox in the group’s recent conduct: despite a reduced operational footprint, Troop 61786 is actively compromising its own anonymity through "sloppy OPSEC." While attempting to stand up and test new botnet infrastructure, the group failed to maintain logical separation between its originating environments. This lack of discipline has resulted in the exposure of three distinct source IP ranges, providing defenders with a high-fidelity targeting map of their current staging assets. By failing to isolate these environments, Troop 61786 has effectively de-anonymized its activity, allowing analysts to link disparate network segments to a single, coordinated campaign. The following technical assessment details how these infrastructure shifts provide a strategic opportunity to collapse the actor's operational tiers through network-level mapping.

2. Infrastructure and Activity Analysis

In CTI, infrastructure mapping serves as the foundation for proactive defense. By meticulously analyzing "source-to-target" patterns—the telemetry between an actor’s originating ranges and their staging or command-and-control (C2) assets—analysts can expose the underlying architecture of a botnet. When an actor fails to diversify their connection paths, they provide the "connective tissue" necessary for defenders to map the full extent of their reach.A critical operational failure was observed when Troop 61786 utilized three separate source ranges to interact simultaneously with a centralized target botnet. This cross-range correlation is an amateur error that facilitates the immediate identification of the actor's broader network footprint. The target infrastructure is comprised of three specific IP addresses:  45.201.1.242 45.205.1.243 , and  45.205.1.244 . These assets are hosted by  VPSVault  in  Brazil .The "so-what" of this activity lies in the total collapse of operational compartmentalization. By hitting the exact same VPSVault targets from all three source ranges, Troop 61786 has "cross-contaminated" its infrastructure. In a mature operational model, a compromise of one source IP should not lead to the discovery of others; however, these shared target IPs now function as a definitive pivot point. If a defender identifies traffic from any single source node, they can pivot to the VPSVault targets and subsequently identify every other range in the actor’s inventory. This strategic error effectively negates the group's attempts at redundancy and provides a high-confidence link between seemingly unrelated IP blocks. The subsequent technical indicators facilitate the translation of this analysis into actionable defensive controls and rigorous network monitoring.

3. Network Indicator Reference (IoCs)

The strategic role of Indicators of Compromise (IoCs) extends beyond simple blocking; they are the primary mechanism for proactive threat hunting. Blacklisting known malicious source infrastructure is essential for preventing initial access and identifying the actor's footprint within organizational telemetry.

Target Botnet Infrastructure

The following IPs constitute the destination infrastructure currently being staged or utilized by Troop 61786.| Target Botnet IP | Provider / Location || ------ | ------ || 45.201.1.242 | VPSVault / Brazil || 45.205.1.243 | VPSVault / Brazil || 45.205.1.244 | VPSVault / Brazil |

Source Infrastructure Breakdown

The following originating IPs have been identified as controlled by Troop 61786. To satisfy the technical observation of "three ranges," these IPs have been categorized by their respective subnet clusters.

           Source Range 1: 106.120.218.x

  • 106.120.218.147

  • 106.120.218.152

  • 106.120.218.181

  • 106.120.218.60

  • 106.120.218.34

  • 106.120.218.233

  • 106.120.218.179

  • 106.120.218.11

     Source Range 2: Subnet Cluster A

  • 218.30.23.11

  • 114.244.130.16

  • 221.216.117.22

     Source Range 3: Subnet Cluster B

  • 123.181.192.51

  • 124.64.23.2

Defensive Utility Analysis

These indicators should be integrated into Security Information and Event Management (SIEM) systems and perimeter defenses to trigger high-severity alerts. Specific detection logic should be implemented to identify multi-source ingress from these blocks toward shared internal assets or the known VPSVault targets. Because the actor's OPSEC failures have fundamentally linked these ranges, any observed activity from these IPs provides a high-confidence signal of a coordinated Troop 61786 operation. Organizations should prioritize egress filtering to the VPSVault IPs and ingress monitoring of the three identified source ranges.While Troop 61786 has scaled back the volume of its activity, the persistent evolution of their infrastructure requires vigilant monitoring to ensure that any resurgence in operational scale is met with an informed and robust defense.



Thursday, August 6, 2026

The Wandering Identity – Troop 61786’s habits outlast their infrastructure

The "pro" hackers at Troop 61786 are back at it under Wang's supervision, but their OPSEC is still a disaster. These operators are still likely playing video games directly from their C2 infrastructure and logging into their official PLA accounts from victim networks. 🎮💻 If you're defending a network, you need to watch for these specific indicators NOW:

  • Active Targeting: 221.216.117.22 over port 4501.

  • Infrastructure Lead: Connections to Blue Tech Technologies via 216.180.229.4 (port 999).

  • New Infrastructure Block (port 5995):

    • 57.128.28.86, 51.15.238.80, 51.159.97.251

    • 51.159.136.27, 57.128.29.136, 94.237.65.52

    • 94.237.75.228, 212.47.234.168

When your adversaries are this loud, use it to your advantage.


Monday, August 3, 2026

Troop 61786’s Return: New IPs, Same Old Tactics

Troop 61786 has resurfaced, with activity emanating from the 106.38.113.0/24 and 106.120.218.0/24 source ranges as they attempt to conceal their identities. Alongside these known ranges, there has been a recent surge in activity from new IP addresses, specifically 124.64.23.2 and 221.216.117.22, which have been observed communicating with ASN 749.
 
These actors are actively scanning and probing for vulnerabilities using their standard ports—80, 443, and 0 (ICMP)—while also utilizing more unusual ports such as 7000 and 8567. Their targeting remains focused on the defence, telecommunications, and technology sectors, but the scope of their operations also includes education and government organizations
 

 


Tuesday, July 28, 2026

More investigations into Troop 61786

 Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associated with APT5— I intend to provide periodic updates as I continue to track their activities. I wanted to share some more observations regarding their evolving tactics and hope to share more detailed findings soon as my investigation progresses.

Troop 61786 continues to exhibit sloppy tradecraft and poor OPSEC despite their desperate attempts to shift between infrastructure services to hide their tracks. While they have utilized the JDY Botnet and specific IP addresses like 181.189.10.216 and 45.154.159.12 to conceal their movements, their underlying lack of skill remains evident. Their amateurish security practices have likely  compromise the operations of more refined PRC actors, such as Volt Typhoon, who often target the same networks. A major operational failure occurred in March 2026 when the group attacked Telekomunikasi Indonesia (PT); during this engagement, they likely left significant amounts of personal data across the victim's network.

The group's global targeting remains wide but messy, impacting utility providers in the United States as well as the education sectors in Chile and Indonesia. To facilitate these operations, they rely on several VPS providers, including Contabo Gmbh, Hetzner, Beijing Volcano Engine Technology, Techoff Srv Limited, and Ucloud Information Technology. Despite using protocols such as TCP, ICMP, UDP, and GRE, their technical footprint is easily tracked due to recurring mistakes. Ultimately, their reliance on the JDY Botnet has failed to provide the professional cover they seek, leaving their infrastructure and lateral movements visible to investigators.



Friday, July 3, 2026

Update: Tactical Shifts and New Indicators for Troop 61786 (APT5)

Following my initial investigation into the six officers within the PRC People's Liberation Army (PLA) Troop 61786—a group associated with APT5—we have observed a significant shift in their operational infrastructure.

The Silence of the Primary Range:

Since my last report exposed their primary source range, the 106.120.218.0/24 block has gone largely quiet. This is a classic reaction to public exposure; however, the unit is far from dormant.

New Infrastructure and Evasive TTPs:

While the original range is cold, limited tactical activity has begun emerging from new specific IP addresses:

  • 106.120.218.163

  • 106.120.217.136

To mask their movements and bypass standard security filters, the group has pivoted to using random high ports, including:

  • 9996, 9998, 10002, 10006, 10007, and 1008.

This is a departure from their previously identified use of non-standard ports like 8080, 8443, and 4433, and their reliance on the WireGuard protocol (UDP 51820) for obfuscation.

Forensic Artifacts: "Noisy" Operations Persist:

Despite these attempts to "hide" within high-port traffic, Troop 61786 continues to demonstrate the same unsophisticated tradecraft noted in our earlier Singapore-based VPS analysis. Their operations remain "noisy," leaving behind a trail of forensic artifacts that allow us to continue tracking their lateral movement and infrastructure connections.

Recommendations for Defenders:

Organizations should update their blocklists and monitoring alerts to include:

  1. IP Ranges: Continued monitoring of 106.38.113.0/24 and the new active IPs listed above.

  2. Port Auditing: Unusual outbound or inbound traffic on the newly identified high ports (9996–10008).

  3. Behavioral Analysis: Look for artifacts similar to those left by previous Troop 61786 campaigns, as their fundamental methodology remains consistent despite the infrastructure shift.

The bottom line: They can change their IPs and ports, but their patterns remain visible. You can run, but you can’t hide.

 Follow me on X (https://x.com/calewnfd)  

Wednesday, June 3, 2026

Investigation into APT 5 and their inner workings of PLA Troop 61786


I am relatively new to the cybersecurity community and I have tracked low-level, criminal groups who conduct computer network exploitation (CNE). My method of investigating criminal activity begins with sleuthing the dark web for tipping information. From there, I overlay leaked CNE data and TTPs with persona information. I began tracking a subset of what was assessed to be low level criminal activity, which actually turned out to be a group of six officers working together within the PRC People's Liberation Army (PLA) Troop 61786. This group appears to be associated with Advanced Persistent Threat 5 (APT5).

My starting point for this investigation was Singaporean-based IP 5.188.34.116, which was a virtual private server (VPS) associated with G-Core Labs. A review of the VPS data from this IP on the dark web revealed that the user had unsophisticated tradecraft as evidence by the significant amount of PII and forensic artifacts left behind. This data point served as the foundation for my investigation and resulted in the identification of the below PLA officers’ identities, their tradecraft, potentially criminal behavior according to Chinese laws, and blatant corruption within PLA Troop 61786. I was able to attribute these officers to Troop 61786 thanks to Shi Qijiang's association of his work address “Haidian District, Hanjiaguan Military Compound, Beijing” to his SF Express and YTO accounts. 

This team’s tradecraft is consistent with that of the least sophisticated CNE actors across the globe. I am unsure if this low-level tradecraft is derived from the team’s laziness, over-reliance on CNE technology to obscure or hide their subpar tradecraft, or ignorance. On one hand, the team utilized anonymization infrastructure services to conceal their identities, while also playing video games via Battlenet on their procured C2 infrastructure. In this same vein, they also utilize their C2 infrastructure to conduct personal business whether it be personal banking, reading emails, or signing into their PLA accounts. PS team lead Wang Huidong may want to update his password at http://mall.plap.cn/users/sign_in.html- “789044” is a rather weak password. 

This group frequently targeted and conducted CNE against several telecommunications providers in places like Southeast Asia and the United States. They appear to heavily rely on rudimentary scripts to streamline their targeting and reconnaissance activities. The team also relies on publicly available CVEs to gain initial access or footholds into targeted networks. Anything beyond noisy scanning activity and outdated CVEs seems very complicated for this team of six, which has ultimately led to the compromise of activity of more refined CNE actors within the PRC such as Volt Typhoon targeting the same networks, companies and educational institutions. 

This team has shown a propensity to conduct criminal and corrupt activities in violation of Chinese law. The team profited from the use of cryptocurrency mining tools while conducting their daily duties with Troop 61786, likely without the approval of their superiors or the PRC government as evidenced by the artifacts left on the aforementioned Singaporean-based VPS. While the whole team was involved in the corrupt activity, team leader Wang Huidong and team member Lyu Ning benefited the most from their investments in the Etherium cryptocurrency. While this activity happened on the job and leveraged their C2 infrastructure to carry out the purchases, they have transferred and stored their wealth from these sales in offshore bank accounts.

Specifically, the six-person team was associated with crypto hash 0x498E920C4710b600179779d6A30cDAf7f592aE04 and utilized the “Bminer” tool which was used while conducting fraudulent CNE activity. Lyu also has shown a propensity for certain immoral proclivities, as evidenced by his account on AdultFriendFinder.com with username “fatox2008”. This type of service is prohibited in the PRC based on existing laws; however, it seems these types of activities and corruption are acceptable within the PRC government for their military officers in Troop 61786.

Troop 61786 Team Members: 

Wang Huidong / 王辉东 (Chinese name)

Email Addresses: 

whenner@163.com (primary email address)

wuyingsuixing@126.com (associated with multiple online services)

tieshan@public.ty.sx.cn (associated with 17jifen.com)

National ID: 640302198611160017

DOB: 16th November, 1986

Birthplace: Ningxia Autonomous Region

Sex: Male

Phone Numbers: 

8613811160360 (associated with multiple online services)

8618744040597

8615650737621

Online Services: 

JD.com (multiple accounts with different usernames and passwords)

17173.com (multiple accounts with the username "whenn" and "whenner")

NetEase (126.com / 163.com) (multiple accounts with the username "whenner" and "wuyingsuixing")

whenner (associated with multiple online services, including 17173.com, yue.com / 123tv.com, and replays.net)

wuyingsuixing (associated with JD.com and other online services)

Contributions to Troop 61786: 

Wang is the leader for this six-person team.

Wang also provides on keyboard support to several of the CNE operations.

Wang received his undergraduate degree in Information Studies and Security from the PLA Information Engineering University (PLAIEU), studied at PLAIEU from September 2004 to June 2008, and pursued a master's degree at Beihang University (BUAA), which he completed in late March 2017.

G-Core Labs VPS for Wang Huidong

IP Address: 5.188.34.116

Location: Singapore, Singapore

Operating System: Windows 7 Professional x64

Username: Administrator

Current Language: Chinese (Simplified, PRC)

TimeZone: (UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi

Hardware Information: 

CPU: Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz, 6 Cores

Graphics Cards: 

Intel(R) UHD Graphics 630

NVIDIA Quadro M4000

RAM: 32.6 GB (34186715136 bytes)

Installed Software: 

Browsers: 

Google Chrome (94.0.4606.61)

Mozilla Firefox (93.0)

Internet Explorer (8.00.7600.16385)

Other Software: 

GNS3 (2.2.16)

Microsoft Visual C++ 2005-2019 Redistributables (multiple versions)

NVIDIA Stereoscopic 3D Driver (7.17.13.7500)

Realtek High Definition Audio Driver (6.0.1.8470)

WinPcap 4.1.3 (4.1.0.2980)

Cookies and Online Activities: 

Wang was logged into multiple online services, including BattleNet, 163.com, Weibo, QQ, CSDN, Zhihu, and Bilibili.

Wang visited various websites related to technology, gaming, e-commerce, and social media.

Wang used the VPS to conduct open-source research on Avaya devices.


Lyu Ning / 吕宁 (Chinese name)

Alternate Names: 

Liu Ning (刘宁)

LV Ning

Identifiers: 

Email Addresses: 

snow1014@163.com

fatox2008@gmail.com

fatox2009@yahoo.com

liuming780707@yahoo.com

laurence.jados@yahoo.com

jean_luc_bolle@yahoo.com

fatox.fatox@yahoo.com

snow801014@163.com

Phone Numbers: 

8613683150507

8613691513981

National ID: 210106198010145211

DOB: 14th October, 1980

Birthplace: Liaoning Province

Sex: Male

Services and Usernames: 

AdultFriendFinder.com - fatox2008

Yahoo.com - fatox2009, liuming780707, laurence.jados, jean_luc_bolle, fatox.fatox

LinkedIn.com - (associated with fatox2008@gmail.com)

JD.com - snow801014, fatox801014

forum.eviloctal.com - fatox1980

online.sh.cn - 【战】征战づ肥牛2008

tgbus.com - fatox

PCOnline.com - fatox20082008

vivo.com - (associated with 13683150507)

Contributions to Troop 61786: 

Lyu frequently configures the team’s exploits as they are conducting target development.

Examples of his support include changes made to open-source CVEs when the team exploited a telecommunications provider and moved laterally within the network to attempt access to infrastructure associated with the United States Government.


Zhang Yifan/ 张一帆 (Chinese name)

Phone Numbers: 

8613701234705 (associated with multiple online services, including JD.com, vivo.com, Alipay, and Tencent)

National ID: 150204198603261214

DOB: 26th March, 1986

Birthplace: Inner Mongolia

Sex: Male

Email Addresses: 

171700a@163.com (associated with JD.com)

907516088@qq.com (associated with Tencent and QQ users)

Online Services: 

JD.com (username "Zy_xtp")

vivo.com (associated with phone number 8613701234705)

Alipay (associated with phone number 8613701234705)

Tencent (associated with phone number 13701234705 and QQ ID 907516088)

QQ users (QQ ID 907516088)

weibo.com (associated with phone number 13701234705)

Personal Information: 

Name: Zhang Yifan / 张一帆 (Chinese name)

Contributions to Troop 61786: 

Zhang set up and managed the team’s CNE infrastructure.


Shi Qijiang/ 石其江 (Chinese name)

Phone Numbers: 

8613982290422 (associated with vivo.com)

8613439709218 (associated with multiple online services, including SF Express, YTO, and JD.com)

National ID: 110105197211131831

DOB: 13th November, 1972

Birthplace: Beijing, China

Sex: Male

Online Services: 

JD.com 

friend8899 (associated with 8613439709218)

SF Express 

associated with 8613439709218 and address "Haidian District, Hanjiaguan Military Compound, Beijing"

YTO 

associated with 8613439709218 and address "Haidian District, Hanjiaguan Military Compound"

Alipay 

associated with 8613439709218

WeChat 

wxid_pzc1n845hh6aq2 (associated with 13439709218)

wxid_3q8v4kwuqcm2qd (associated with 13439709218)

Personal Information: 

Address: Haidian District, Hanjiaguan Military Compound, Beijing

Contributions to Troop 61786: 

Shi served on the team as a vulnerability researcher in support of their CNE requirements.

Shi has provided the team with vulnerabilities that were then utilized to exploit websites associated with the United States Government.

 

Wu Bi/ 吴比 (Chinese name)

Phone Numbers: 

8618319041629 (associated with China UnionPay)

National ID: 220322197903214796

DOB: 21st March, 1979

Birthplace: Jilin Province 

Sex: Male

Email Addresses: 

45662511@qq.com (associated with multiple online services, including QQ Groups, NetEase, and pipix.com)

wbisdragon@gmail.com (associated with forum.eviloctal.com and pipix.com)

wbisdragon@hotmail.com (associated with ccidnet.com)

Online Services: 

QQ Groups (multiple groups with the username "Wu Bi" and "Wu Erbao")

NetEase (126.com / 163.com) (multiple accounts with the username "luckywubi")

pipix.com (multiple accounts with the username "luckywubi")

forum.eviloctal.com (username "luckywubi")

ccidnet.com (username "luckywubi")

Zol.com.cn (username "luckywubi")

Personal Information: 

Address: Siping City, Lishu County, Jilin Province, and Shenzhen, Guangdong Province

IP Addresses: 

123.116.146.58 (associated with forum.eviloctal.com)

123.116.144.141 (associated with ccidnet.com)

Contributions to Troop 61786: 

Wu often provides hands on keyboard support to this team’s CNE efforts as a CNO.


Xiao Feng/ 肖锋 (Chinese name)

Email Accounts: 

xiao@vip.qq.com (primary email address)

188589342@qq.com (associated with domain registration)

765800668@qq.com (associated with domain registration)

zjfblog@qq.com (associated with domain registration)

Phone Numbers: 

8615110030883 (associated with multiple online services and domain registration)

8616673052122 (associated with China UnionPay)

8618780727337 (associated with domain registration)

National ID: 430723198505246014

DOB: 24th May, 1985

Birthplace: Hunan Province 

Sex: Male

Domain Registrations: 

53xinke.com (registered multiple times with different registrars and contact information)

cdwlzxx.com (registered with HiChina Zhicheng Technology Ltd.)

Usernames and Associated Services: 

xiao1011 (Anjian.com)

xiaofeng6862 (JD.com)

xiaofeng6863 (JD.com)

xiaomin (JD.com)

776503455 (NetEase, zhenai.com, 766.com)

868123456 (houdao.com)

Personal Information: 

Address: Changde City, Hunan Province, China (associated with China UnionPay)


Contributions to Troop 61786: 

Xiao set up the team’s infrastructure and conducted general scanning or reconnaissance activities. Xiao’s specialties include VPN tunnels for infrastructure, building python scripts for parsing and various internet protocols, and utilizing publicly available scanning tools for target research.


I was able to track the actors “first hop” IPs from their source range by investigating forensic artifacts within their C2 infrastructure. The most notable IPs are listed below and belong to China Telecom. I am almost certain China Telecom has to be aware of the nefarious activity being carried out via their networks. 

218.30.23.11

123.181.192.51

106.38.113.244

106.38.113.247

106.38.113.250

106.38.113.243

106.38.113.246

106.38.113.248

106.38.113.249

106.38.113.251

106.38.113.254

106.38.113.245

106.38.113.252

106.38.113.253

106.120.218.131

106.120.218.134

106.120.218.135

106.120.218.137

106.120.218.149

106.120.218.152

106.120.218.156

113.25.85.194

119.147.226.22

 

For more information on my findings follow us on X (x.com/calewnfd)! 


Troop 61786’s Evolving C2 Footprint: Standalone Nodes, ASN 749 Targeting, and Academic Exploits

The operators behind PLA Troop 61786 (APT5) are at it again, attempting to sustain their cyber-espionage operations while continuing to e...