Uptime Hamster: 27d 15h 55mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza apos

apos

2 incidentes 1 paises 1 sectores threat-actor RU Ultimo: 2026-06-29
Aliases: Putter Panda, PLA Unit 61486, TG-6952, técnicas, PISCES, LOGJAM o SOGU, obtención de credenciales, oficiales para este grupo, lo que sugiere una operación bien coordinada, un enfoque orientado a la sigilocidad, Trochilus RAT, PlugX, EvilGrab, 3102 variant of 9002 RAT, Seven Pointed Dagger, otros, lo que sugiere una amplia gama de herramientas, técnicas utilizadas en operaciones de amenaza a largo plazo
Ver en IntelTracker → APTTrail →
Apos is a ransomware group that emerged in April 2024, distinguishing itself as a data-broker or leak-only operation rather than employing traditional file-encryption. This group focuses on data exfiltration, threatening to leak or sell stolen information as their primary means of extortion. Unlike many ransomware operations, Apos has not been observed to conduct file encryption. Reporting indicates that its activity tapered off after a few incidents, potentially suggesting it was a short-lived operation or a one-time campaign, and its technical details, such as specific encryption algorithms or ransom notes, remain largely undocumented publicly. The group is sometimes referred to as Apos Security.

Aliases del actor

Putter PandaPLA Unit 61486TG-6952técnicasPISCESLOGJAM o SOGUobtención de credencialesoficiales para este grupolo que sugiere una operación bien coordinadaun enfoque orientado a la sigilocidadTrochilus RATPlugXEvilGrab3102 variant of 9002 RATSeven Pointed Daggerotroslo que sugiere una amplia gama de herramientastécnicas utilizadas en operaciones de amenaza a largo plazo"Energy technology""G20""NGOs""Dissident Groups"MimikatzWmiExectécnicas de persistenciaItaDukese ha enfocado en regiones geopolíticamente sensiblesincluyendo TibetUyghurSiriaIránAfganistán

Actores similares

Conquerors Electronic Armyapt · 0Operation DRBControlapt · 0apt-desertfalconactor · 1Desert Falconsapt · 0Container Orchestration Jobactor · 1Eloquent Pandaapt · 0apt-stealthfalconactor · 1PhantomControlapt · 0Confuciousapt · 0Data from Configuration Repositoryactor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: apos
Webunknownnitter.netMalwareHunterTeam: A possible interesting, low detected sample that was seen from Italy has @ET_Labs "ET MALWARE Win32/Darkme Trojan Checkin M1" traffic match to that IP address. In case correct, that IP can be related to Evilnum APT... ‍ As soon as @smica83 has time, the sample will be uploaded to Bazaar and then anyone can look. cc @marsomx_ @G60930953
X/Twitterunknownx.comMalwareHunterTeam: A possible interesting, low detected sample that was seen from Italy has @ET_Labs "ET MALWARE Win32/Darkme Trojan Checkin M1" traffic match to that IP address. In case correct, that IP can be related to Evilnum APT... ‍ As soon as @smica83 has time, the sample will be uploaded to Bazaar and then anyone can look. cc @marsomx_ @G60930953
DLS / onionofflineyrz6bayqwhleymbeviter7ejccxm64sv2ppgqgderzgdhutozcbbhpqd.onionCTI.FYI
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (OSINT)

ArgentinaAustraliaBrazilCanadaCzech RepublicGermanySpainFranceUnited KingdomIndia

Sectores atacados

Healthcare (1)

Sectores objetivo (OSINT)

Construction of BuildingsOther Information ServicesSoftware PublishersAir TransportationManufacturingPublic AdministrationEducational ServicesWholesale TradeData Processing ServicesSpace & Defense

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com