Uptime Hamster: 22d 12h 55mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza Carderbee

Carderbee

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: APT CARDERBEE
Ver en IntelTracker → APTTrail →
Carderbee is an advanced persistent threat (APT) group that emerged in 2023, identified by Symantec's Threat Hunter Team. The group is strongly associated with China and is primarily motivated by information theft and espionage. What distinguishes Carderbee is its sophisticated use of software supply chain attacks, specifically compromising the legitimate Chinese software Cobra DocGuard Client to deliver Microsoft-signed malware, predominantly the Korplug (PlugX) backdoor, to select high-value targets. This group focuses its operations on organizations in Hong Kong and other parts of Asia. While similar attack vectors have been attributed to other China-linked groups like APT27 (Budworm/LuckyMouse), Symantec assigned the new moniker Carderbee due to insufficient evidence to definitively link the observed activity to an existing threat actor.

Aliases del actor

APT CARDERBEE

Actores similares

apt-carderbeeactor · 1apt-c-01actor · 2apt-c-27actor · 2apt-45actor · 2apt-c-37actor · 1apt-c-23actor · 1hellsing-aptactor · 1apt-c-44actor · 1apt-c-38actor · 1apt-c-12actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupsymantec-enterprise-blogs.security.comAPT CARDERBEE indicators and references
Repositorioupgithub.comAPT CARDERBEE indicators and references
DLS / leak siteupraw.githubusercontent.comAPT CARDERBEE indicators and references
Motivacion