Stealth Tactics – Chinese APT Groups Leverage Proxies and VPNs to Conceal Operations
ID: 3c6e07b3-2c6c-5977-a7f2-65ab36c91d7a
STIX ID: report--3c6e07b3-2c6c-5977-a7f2-65ab36c91d7a
Feed Name: Cyber Press
**Executive summary:** A recent data dump published on DDoSecrets allegedly exposed workstation files linked to a suspected North Korean APT (Kim‑suky), revealing an anonymization infrastructure that leverages Trojan proxy nodes, domain fronting/SNI tricks, and a shared SSL certificate (*.appletls.com) observed across thousands of IPs. Analysis connects commercial VPN/proxy providers (GaCloud/WgetCloud) and tooling (Txray/Xray-core) to adversary C2 and IP rotation, with intelligence firms flagging over 1,700 nodes—underscoring how legitimate anonymization services can be repurposed for sophisticated, deniable APT operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
