Resources
White Papers
[White paper] Seeing the Pattern Behind The Attacks: APAC Intelligence for CISOs Worldwide
![[White paper] Seeing the Pattern Behind The Attacks: APAC Intelligence for CISOs Worldwide](https://teamt5-back.e-s.tw/api/files/teamt5-from-an-apac-threat-intelligence-pioneer-to-a-global-leader_en_pic.png)
APAC is now a proving ground for some of the world’s most sophisticated cyber actors. From state-backed groups to commercial contractors and organized cybercrime, adversaries in the region move quickly, reuse infrastructure, and mix espionage with financially motivated operations. For CISOs, the challenge is no longer a lack of alerts — it’s the lack of context. This white paper explains why an adversary-centric intelligence approach is essential for APAC defenders. Instead of collecting more indicators, it focuses on understanding who the attackers are, how they operate, and what drives their campaigns. Drawing on TeamT5’s decades of regional research, it breaks down real cases including the i-Soon contractor leak and the Mackay Memorial Hospital ransomware attack, to show how attacker ecosystems really function. Download the white paper to gain a comprehensive view of APAC threat actors to plan your defense strategy for long-term security from a new perspective.

TeamT5 is a leading brand in delivering Asia Pacific intelligence. In this article, we summarize the threat landscape of advanced persistent threats (APT) in the Asia-Pacific region in 2024, not only provide annual observations, but also point out the cyber threats worth paying attention to in 2024. This article is an excerpt version which summarizes key statistics. To obtain the complete threat intelligence report, you may fill up the form at the bottom to obtain the “APT Threat Landscape in APAC 2024: Blurred Lines of Cyber Attacks” report. To discover similar cyber threat intelligence which is focused in the Asia-Pacific region, please sign up for the trial of our award-winning threat intelligence platform ThreatVision. Threat Statistics in 2024: Data & Observations In 2024, until the end of November, TeamT5 actively tracked 30 new vulnerabilities being exploited in the wild, along with around 500 attack operations across 42 countries, which we attributed to 73 known adversaries and more than 200 malware / hacking tools being used. We also identified 45 victims being compromised in 9 countries and tried to notify through our trustworthy partners. And helped 33 IR cases for our customers. You could imagine all the above data contributing to our intelligence reports. Generally speaking, most of them show a tendency of increasing. TeamT5 is actively tracking vulnerability exploitation attacks in the wild. In 2024, 30 widespread attacks were tracked by TeamT5, around 400 victim hosts across 21 countries were identified to be compromised. We would like to highlight that 5 of them are email system related and 14 are exploiting edge devices, indicating they are high priorities of threat actors to access targets. Our research also shows EtherBei (aka Flax Typhoon) to be the most active threat actors to adopt these exploits. During the course of our research, we also discovered some threat actors built their botnet or so called Operation Relay Box network by implanting malware like GobRAT, NatWalk and GenSeven. Lastly, there’s also a tendency that more management services of edge devices are being exploited, such as FortiManager, Versa Director or Palo Alto Firewall, e.t.c., meaning that threat actors might compromise multiple entities by intruding on one device. We believe this is a threat that management service providers or big enterprises should be aware of.
![[Whitepaper] Cyber Threats against Taiwan’s 2024 Presidential Election](https://teamt5-back.e-s.tw/api/files/OG-image_1200x630_1.png)
2024 is a record-breaking year for elections around the globe, with over 60 countries home roughly half of the world’s population is set to hold national elections. On 13 January 2024, Taiwan kicked off this super-election year with its presidential and legislative elections. At TeamT5, we are pleased to see that the election concluded smoothly, without any successful disruptions by cyber attackers. We believe this achievement is a result of the hard work and dedication of many individuals and organizations. Their collective efforts have ensured the election process remained secure and trustworthy. Despite the overall success, TeamT5 believes that we must not overlook the challenges posed by state-sponsored cyber threats. Our team has worked tirelessly to identify and analyze numerous malicious activities and disinformation campaigns, particularly those associated with state-linked influence operation (IO) actors or Advanced Persistent Threat (APT) groups. This whitepaper will detail the specific tactics, techniques, and procedures (TTP) used by these actors, hoping to provide valuable insights into their operations. The cyber threat landscape is ever-changing, with adversaries constantly improving their attacking methods. During this election cycle, we noticed that these threat actors have enhanced their capabilities, employing more sophisticated and innovative techniques to target a broader array of platforms. This whitepaper not only shares our discoveries but also illustrates the importance of continuously updating our cyber defense strategies to stay ahead of potential threats. We are committed to evolve our threat intelligence to counteract these cyber threats. Through this whitepaper, we aim to share our strategic findings, hoping to equip other democracies, especially those facing upcoming elections, with better understanding of cyberattacks aiming to disrupt the democratic process. We hope it serves as a practical resource for cyber threat intelligence experts in democratic countries, helping them to anticipate and mitigate cyber threats effectively. Research Highlights 1. Prior to the 2024 elections, Taiwan has faced an array of sophisticated cyber threats, all aimed at destabilizing the democratic processes and undermining public trust in the electoral system. Overall, China-nexus actors accounted for a major part of the targeted attacks. 2. Chinese Advanced Persistent Threat (APT) groups have targeted multiple entities in Taiwan, especially the journalism and media industry. Notably, not only pro-democracy or pan-green media have fallen into prey. Our database suggests that domestic television operators and newspapers, some perceived as pro-unification or pro-China, have also been the primary targets. 3. On the other hand, China has also been weaponizing social media platforms to spread disinformation and propaganda against Taiwan. While we observed sparse suspicious activities attacking the ruling party since early 2023, it was not until November that we detected significant influence operations. We summarized three key trends of China’s influence operations during the elections: (1) Expanded Target Scope (2) AI-Enabled Campaigns across Various Platforms (3) Fake News Sites and Whistleblower Sites 4. From late November 2023, we have detected China-nexus hack and leak incidents, corresponding with the following influence operations aimed at diminishing public trust toward Taiwan’s current ruling party, the Democratic Progressive Party (DPP). These campaigns mark a strategic adoption of “hack-and-leak” methods, a notable shift in hybrid warfare tactics. We highlight a significant campaign named “Operation ScoopSpy.” It is very likely that their goals are to sow chaos and discredit pro-democracy politicians regardless of which candidate or political party wins in the elections. 5. China’s approach to influencing Taiwan’s political landscape, particularly around the2024 elections, underscores a long-term strategy. Advanced Persistent Threat (APT) groups and influence operation (IO) actors linked to China have shown a deep understanding of their targets, indicating thorough preparation and research. This meticulous groundwork has led to a troubling synergy between cyber espionage efforts and influence operations. To receive the whole whitepaper, please fill up the form below.
![[Whitepaper] Understanding Threat Intelligence & The Threat Landscape with TeamT5](https://teamt5-back.e-s.tw/api/files/teamt5-from-an-apac-threat-intelligence-pioneer-to-a-global-leader_en_pic.png)
Threat intelligence , also known as cyber threat intelligence (CTI), is a critical aspect of cybersecurity, involving the collection, processing, and analysis of data about potential or current threats to an organization's security. This intelligence is not just raw data but contextual information that helps in understanding threat actors' motives, targets, and attack behaviors. It provides insights into the tactics, techniques, and procedures (TTPs) of adversaries, enabling organizations to prepare, prevent, and identify cyber threats that could exploit valuable resources. This whitepaper will give you overall understanding of threat intelligence and how threat intelligence points out the threat landscape . It contains: - Introduction to Threat Intelligence - Challenges & the Role of Threat Intelligence - Types of Threat Intelligence - The Threat Intelligence Lifecycle - Implementing Threat Intelligence - Threat Intelligence in Action - Future Trends & Developments <br> Fill up the form and receive our whitepaer now!

TeamT5 is a leading brand in delivering Asia Pacific intelligence. In this article, we summarize the threat landscape of advanced persistent threats (APT) in the Asia-Pacific region in 2023, not only provide annual observations, but also point out the cyber threats worth paying attention to in 2024. This article is an excerpt version which summarizes key statistics. To obtain the complete threat intelligence report, you may fill up the form at the bottom to obtain the “APT Threat Landscape in APAC 2023” report. This article is adapted from "2023 H2 Campaign Tracking Report: APT Threat Landscape in Asia". To discover similar cyber threat intelligence which is focused in Asia-Pacific region, please sign up for the trial of our threat intelligence platform ThreatVision. Please indicate on the ThreatVision page that you would like to apply for trial. Preface TeamT5’s cyber threat intelligence research based on well-built data collection and analysis flow. We collect data from multiple sources - malware databases, sandboxes, crawlers, and our threat forensic analysis platform ThreatSonar etc. With careful and rigorous analysis, we come up with intelligence reports for clients and the public to notify potential threats. For 2023, based on TeamT5 data collection and analysis, we found: 411 attack operations in 39 countries 60 known adversary groups tracked 210 malware / hacking tools used Closer Look at Exploits In 2023, we have observed at least 37 CVE exploits that were abused in the wild by threat actors. We see a tendency that more and more exploits targeting edge devices appear, which we marked with color yellow in the right table. These edge devices have no security products to monitor them so threat actors could effectively intrude their target network environments. There are still lots of attacks achieved spear phishing emails but the corresponding tricks are old fashioned, such as: Template Injection Microsoft LNK CHM Macro documents Phishing CVE-2018-0798, CVE-2022-30190, CVE-2023-38831 Closer Look at Malwares We listed the malware distribution in all attacks. Below is the ranking of Top 10 Malwares in 2023 H1 and Top 15 Malwares in 2023 H2 . We compare these two ranks with 4 aspects - Shared tools, Webshell, Cross platform RAT, Shared Quartermaster of Chinese APT. Here is our analysis. 1. About shared tools There are more and more threat actors adopting public or open source tools in their operations. This could effectively reduce their effort to develop their own weapons and also increase the barrier for researchers like us to achieve an effective attribution. 2. About Webshell Web server exploitations have become more and more common nowadays and the importance of webshell keeps increasing. Godzilla, a full featured webshell made by Chinese threat actors, has become the favorite of Chinese APT. It is usually deployed jointly with a small webshell like China Chopper to effectively bypass detections. 3. About Cross Platform RAT There are more and more cross platform or multi platform RAT. The reason behind is nowadays threat actors don’t only focus on Windows platform but will intrude from every possible platform like Linux, MacOS or even Android or iOS. 4. Shared Quartermaster of Chinese APT We have observed an interesting code or feature sharing between different malware used by Chinese APT. This kind of finding makes us highly suspect there is an entity or even private company that is responsible for producing all these remote administration tools and distributing them secretly to various Chinese APT groups. Closer Look at Targeted Countries / Regions by APT Groups From countries / regions aspects, our data shows Taiwan, South Korea, and Japan are the most targeted countries by APT groups. Following them are countries in South or Southeast Asia, such as Vietnam, Philippine, Thailand, or Malaysia, etc. Based on this statistic, we will discuss 3 different victim areas and corresponding active threat actors, they are Taiwan, Northeast Asia, and South/Southeast Asia. No.1 Targeted Country / Region: Taiwan Taiwan is the most targeted country in Asia Pacific. This chart shows the distribution of targeted industry sectors. Compared with our data in the past 2 years (2021-2022), we don’t see dramastic changes. Government, IT, education, or critical infrastructure are still on the top list. People might wonder why APT actors are so interested in the IT sector. We believe the reason is that there are more and more supply chain attacks and these IT companies possess good channels or privileges to access big companies or government entities. It makes the IT sector a perfect hopping point. And one interesting phenomena we have observed is the surging attack against the healthcare industry. We suspect the reason behind the attacks are the Taiwanese government’s effort to join WHA, or China’s ambition to collect personal identification information. In the threat actors' part, there are at least 21 known groups aiming at Taiwan in 2023. Among them are Huapi, Amoeba, and Polaris - they are old faces that are on the top list hitting Taiwan. In the meantime, there is a new face, SLIME13 (also known as FlaxTyphoon by Microsoft). SLIME13’s operations became so wild in 2023 that we have observed more than 100 victim entities in Taiwan. This APT group also aggressively expands their attacks to other countries such as Hong Kong, Japan or South Korea, etc. No.2 Targeted Country / Region: Northeast Asia In the Northeast Asia region, the geopolitical situation has changed dramatically in the past 2 years because Japan and South Korea are united together with the U.S. to defend against their enemies in the neighborhood. For this reason, the topmost targeted sectors include government, think tank, and education. These sectors often hold political documents or do sensitive research for their governments. Another interesting phenomena would be China’s attacks against South Korea which were stealthy and low profile in the past. But now China’s attacks turned to become high profile and public, threat actors such as 曉騎營 or 騰蛇 are some good example. Cryptocurrency sectors in this area are targeted and infiltrated by North Korean actors. For the threat actors part, China and North Korea actors dominate this area. North Korean actors are busy collecting geopolitical intelligence and another mission: earning money for their country. In contrast, Chinese APT operations become more stealthy and harder to detect; there are several big campaigns of Barracuda, Fortigate, Citrix or ArrayVPN vulnerabilities. Many of the events are still under investigation or even uncovered yet. No.3 Targeted Country / Region: South Asia & Southeast Asia The third target country / region is the South Asia and Southeast Asia region. Our observations show attacks in this area are driven by issues of the South China Sea, border issues or belt & road and shift of international organization’s factory. That was reflected in the most targeted sectors - military and critical infrastructure are all closely bundled with these issues. In the southeast Asia region, threat actors from China such as Polaris, Amoeba, Gudiao and Vietnam originated groups such as SLIME43 or OceanLotus are very active in these regions. The interesting part regarding Vietnamese APT groups is that they are not only a big concern of neighboring countries but also the domestic people in Vietnam. Our engagement with Vietnamese customers shows their great fear of being intruded by OceanLotus. In the South Asia region, China is also busy attacking and monitoring their neighbors. People might consider Pakistan to be a good friend of China so they could be spared. In contrast, our data shows Pakistan to be highly targeted and infiltrated by China. Another interesting thing is that India and Pakistan both have their own cyber actors and they are fighting with each other a lot. Conclusion 2023 is a busy year, both for threat actors and defenders. Also, more tensions in geopolitics will keep bringing more cyber attacks. New technology might solve human’s problems, but not for attack and defense scenarios. New technology becomes a new opportunity for attackers as well (e.g. cloud services, AI). The reason is that targeted attacks are human-driven; defenders should address human problems by adopting threat intelligence. No one can be spared in the war in the cyber world, so be prepared! This article is an excerpt version which summarizes key statistics. To obtain the complete threat intelligence report, you may fill up the form at the bottom to obtain the “APT Threat Landscape in APAC 2023” report. This article is adapted from "2023 H2 Campaign Tracking Report: APT Threat Landscape in Asia". To discover similar cyber threat intelligence which is focused in Asia-Pacific region, please sign up for the trial of our threat intelligence platform ThreatVision. Please indicate on the ThreatVision page that you would like to apply for trial.

In the final part of our Information Operation White Paper, we will demonstrate China's Information Operations (InfoOps) targeting the global audience. The first part of the report displays a brief overview of its overt operations which are carried out by state media, embassies, and diplomats. Then we look into the covert operations, which can be observed in pro-China fan pages, content farms, and spam botnet. Last but not least, we provide the case study of "Operation Juiker" on Taiwan's largest forum PTT, which suggests the possibility of the APT (Advanced Persistent Threat) actors entering the threat landscape. Key Takeaways 1. China has escalated the level of overt InfoOps via state-media and diplomats. Chinese state media, diplomats, and embassies are the main actors of Chinese overt InfoOps. They shoulder the task to polish the image of the regime and propagate the narrative of the Chinese Communist Party (CCP). It is noteworthy that their official accounts have obtained an unexpected number of followers in recent years. For instance, four Chinese state media are included in the top 20 most-followed pages on Facebook. Their main audience, apart from the Chinese citizens, are overseas Chinese diaspora, which many of them have rights to vote in countries such as the U.S., Canada, and Australia, thus having the ability to influence a country's politics. 2. Covert InfoOps remain active on Western social media platforms. 2020 is a year which has set many records. This year, the takedowns of covert Chinese social media accounts by Facebook, Twitter, and Google are more frequent than ever. However, even with such efforts, we observed that there are new covert actors emerging across the platforms, while the banned actors keep coming back to the scene by registering new domains and new accounts. We spotted that there is a huge number of Facebook pages with admins located in China dedicated to disseminating Chinese propaganda content originated from Chinese social media platform, Weibo. Besides, there are sophisticated actors that create websites and subtle content to help the Chinese government shaping the narrative for the Hong Kong protest. We also detected numerous networks of pro-China political accounts that demonstrated strong signs of automated behavior. 3. APT actors might have entered the InfoOps threat landscape. The situation is become more alarming as we discovered that the Advanced Persistent Threat (APT) actors might have entered the InfoOps threat landscape. APT actors, typically a state-sponsored group, usually conduct prolonged and targeted cyberattacks to mine highly sensitive data. However, in mid-2020, we identified an InfoOp that can be linked to a notorious Chinese APT group which TeamT5 intelligence team has tracked for years. We discovered that the threat actors had disseminated disinformation about "Juiker," a messaging app developed by Taiwan's research institute and widely used by government units, on Taiwan's largest forum PTT. The operation, which we dub as "Operation Juiker," aimed to discredit Taiwan's intelligence agency and government-backed research institute by spreading disinformation of the messaging app being hacked. 4. It is more crucial than ever to adopt threat intelligence solutions to combat the issue. The abovementioned Operation Juiker has well demonstrated the possibility of "APT + InfoOp" attack model, which involves targeted social media campaigns disseminating disinformation based on highly confidential data. Such situation is super tricky, and it could pose a great threat to democratic countries. In this case, threat intelligence can help provide instant analysis of actor methodologies, suspicious indicators, and potential risks. We suggest that it is crucial for government units, critical infrastructure operators, and major business vendors to apply threat intelligence to combat this issue. If you are interested in this white paper, please fill out the form below and get the full-text PDF.

To confront the emerging threat of China's Information Operation, TeamT5 threat intelligence team publishes this White Paper covering how China conduct information manipulation across Chinese social media platforms. From the 2019 Hong Kong Protest to the 2020 COVID-19 pandemic, China has demonstrated the art of surveillance, censorship, and most importantly, digital propaganda. In this white paper, we focus on China's digital propaganda inside the Great Firewall. We suggest that the regime has developed a unique, organizational, and sophisticated propaganda mechanism, which we dub as "digital propaganda formula." With this formula, the Chinese Communist Party (CCP) has managed to transform all the Chinese social media platforms inside the Great Firewall into an almost total pro-CCP environment. Key Takeaways CCP has strengthened its control over Chinese cyberspace by establishing legislations as well as centralizing administrations, and the "last mile" of its cyber governance is to control public opinion through censorship and digital propaganda. We dub China's sophisticated propaganda mechanism the "digital propaganda formula," which consists of state media, communist youth league, governmental affairs new media, as well as trolling factory. Moreover, CCP's policies have bolstered the industry of "public opinion guidance" in China. The industry practitioners have developed AI and big data-powered systems to help the government to collect, store, and analyze public sentiment. China's formula has polluted the online information environment inside the Great Firewall. We assess that the CCP is trying to project its digital propaganda dominance to foreign social media platforms in order to control the world's discourse power. Following the global pandemic, the world relies on the internet more than ever. Cyber threat actors and influence operators, either state-backed or money driven, are taking the advantage to conduct information operation. TeamT5 threat intelligence team aims to deliver actionable intelligence and penetrating analytics and contribute to the safeguarding of cyberspace. If you are interested in this white paper, please fill out the form below and get the full-text PDF.