Operation Tainted Love
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Operation Tainted Love, which emerged in the first quarter of 2023, is attributed to a Chinese state-sponsored cyberespionage actor, demonstrating an evolution of tooling previously associated with Operation Soft Cell. This actor's primary motivation is cyberespionage, focusing on reconnaissance, credential theft, lateral movement, and data exfiltration with specific tasking requirements. What distinguishes this group is its deployment of a custom, highly maintained, and versioned credential theft malware, mim221, equipped with advanced anti-detection capabilities. The group is closely linked to Operation Soft Cell and Gallium, and shares possible connections with APT41, making it important to distinguish this campaign from a separate, similarly named operation by Indian state-backed actors targeting Italian defense firms.