Post

Investigation into APT 5 and PLA Troop 61786

Investigation into APT 5 and PLA Troop 61786

Threat Review Journal: Investigation into APT 5 and PLA Troop 61786

I began tracking a subset of what was assessed to be low-level criminal activity, which actually turned out to be a group of six officers working together within the PRC People’s Liberation Army (PLA) Troop 61786. This group appears to be associated with Advanced Persistent Threat 5 (APT5). According to the investigation, my starting point was Singaporean-based IP 5.188.34.116, a virtual private server (VPS) associated with G-Core Labs. A review of the VPS data from this IP on the dark web revealed that the user had unsophisticated tradecraft, as evidenced by the significant amount of PII and forensic artifacts left behind. This data point served as the foundation for my investigation and resulted in the identification of the below PLA officers’ identities, their tradecraft, potentially criminal behavior according to Chinese laws, and blatant corruption within PLA Troop 61786. I was able to attribute these officers to Troop 61786 thanks to Shi Qijiang’s association of his work address “Haidian District, Hanjiaguan Military Compound, Beijing” to his SF Express and YTO accounts.

This team’s tradecraft is consistent with that of the least sophisticated CNE actors across the globe. On one hand, the team utilized anonymization infrastructure services to conceal their identities, while also playing video games via Battlenet on their procured C2 infrastructure. In this same vein, they also utilize their C2 infrastructure to conduct personal business, whether it be personal banking, reading emails, or signing into their PLA accounts. PS team lead Wang Huidong may want to update his password at PLA Sign In - “789044” is a rather weak password. This group frequently targeted and conducted CNE against several telecommunications providers in places like Southeast Asia and the United States. They appear to heavily rely on rudimentary scripts to streamline their targeting and reconnaissance activities. The team also relies on publicly available CVEs to gain initial access or footholds into targeted networks. Anything beyond noisy scanning activity and outdated CVEs seems very complicated for this team of six, which has ultimately led to the compromise of activity of more refined CNE actors within the PRC, such as Volt Typhoon targeting the same networks, companies, and educational institutions.

The report also highlighted that this team has shown a propensity to conduct criminal and corrupt activities in violation of Chinese law. The team profited from the use of cryptocurrency mining tools while conducting their daily duties with Troop 61786, likely without the approval of their superiors or the PRC government, as evidenced by the artifacts left on the aforementioned Singaporean-based VPS. While the whole team was involved in the corrupt activity, team leader Wang Huidong and team member Lyu Ning benefited the most from their investments in Ethereum cryptocurrency. While this activity happened on the job and leveraged their C2 infrastructure to carry out the purchases, they have transferred and stored their wealth from these sales in offshore bank accounts. Specifically, the six-person team was associated with crypto hash 0x498E920C4710b600179779d6A30cDAf7f592aE04 and utilized the “Bminer” tool while conducting fraudulent CNE activity.

Read full article

This post is licensed under CC BY 4.0 by the author.