Uptime Hamster: 11d 20h 54mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza apos

apos

2 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-06-29
Aliases: lo que sugiere una red de actividades coordenadas, Comment Panda, PLA Unit 61398, TG-8223, APT1, BrownFox, Group 3, GIF89a, ShadyRAT, Shanghai Group, Byzantine Candor, G0006, TG-0110, APT3, Buckeye, UPS Team, Group 6, Boyusec – the Guangzhou Boyu Information Technology Company
Ver en IntelTracker → APTTrail →
Apos is a ransomware group that emerged in April 2024, distinguishing itself as a data-broker or leak-only operation rather than employing traditional file-encryption. This group focuses on data exfiltration, threatening to leak or sell stolen information as their primary means of extortion. Unlike many ransomware operations, Apos has not been observed to conduct file encryption. Reporting indicates that its activity tapered off after a few incidents, potentially suggesting it was a short-lived operation or a one-time campaign, and its technical details, such as specific encryption algorithms or ransom notes, remain largely undocumented publicly. The group is sometimes referred to as Apos Security.

Aliases del actor

lo que sugiere una red de actividades coordenadasComment PandaPLA Unit 61398TG-8223APT1BrownFoxGroup 3GIF89aShadyRATShanghai GroupByzantine CandorG0006TG-0110APT3BuckeyeUPS TeamGroup 6Boyusec – the Guangzhou Boyu Information Technology CompanyLtd1Pitty PandaG0011Paladin RATCVE-2015-2545TaiwanThailandTamper Pandarefuerzan la necesidad de monitoreo continuo"Hong Kong dissidents"indica una posible operación transnacional o regional8KeyBoys

Actores similares

Conquerors Electronic Armyapt · 0Operation DRBControlapt · 0apt-desertfalconactor · 1Desert Falconsapt · 0Container Orchestration Jobactor · 1Eloquent Pandaapt · 0apt-stealthfalconactor · 1PhantomControlapt · 0Stealth Falconapt · 1Confuciusapt · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: apos
Webunknownnitter.netMalwareHunterTeam: A possible interesting, low detected sample that was seen from Italy has @ET_Labs "ET MALWARE Win32/Darkme Trojan Checkin M1" traffic match to that IP address. In case correct, that IP can be related to Evilnum APT... ‍ As soon as @smica83 has time, the sample will be uploaded to Bazaar and then anyone can look. cc @marsomx_ @G60930953
X/Twitterunknownx.comMalwareHunterTeam: A possible interesting, low detected sample that was seen from Italy has @ET_Labs "ET MALWARE Win32/Darkme Trojan Checkin M1" traffic match to that IP address. In case correct, that IP can be related to Evilnum APT... ‍ As soon as @smica83 has time, the sample will be uploaded to Bazaar and then anyone can look. cc @marsomx_ @G60930953
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

ArgentinaAustraliaBrazilCanadaCzech RepublicGermanySpainFranceUnited KingdomIndia

Sectores atacados

Healthcare (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersAir TransportationManufacturingPublic AdministrationEducational ServicesWholesale TradeData Processing ServicesSpace & Defense

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com