Uptime Hamster: 10d 9h 34mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Pacha Group

Pacha Group

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Ver en IntelTracker → APTTrail →
Pacha Group is a China-nexus threat actor primarily focused on cryptojacking activities, first identified in September 2018 with the discovery of its Linux.GreedyAntd cryptocurrency miner. Unlike groups involved in espionage or data theft, Pacha Group's core objective is financial gain through illicit cryptomining, distinguishing it from broader advanced persistent threat (APT) definitions. The group is notably characterized by its aggressive tactics against rival cryptomining operations, actively seeking to disrupt competitors like the Rocke Group by blacklisting their infrastructure. Despite being labeled with attributes often associated with state-sponsored actors in some general threat intelligence summaries, specific, verified intelligence confirms its specialization in resource hijacking for cryptocurrency generation rather than geopolitical objectives. The group operates primarily within cloud-based environments, targeting vulnerable Linux servers.

Actores similares

pacha-groupactor · 1silentransomgroupactor · 36GroupIB_TIactor · 11bonacigroupransomware · 2thegreenbloodgroupransomware · 2vanirgroupransomware · 2SilentRansomGroupactor · 2the-green-blood-groupactor · 2apt-equationgroupactor · 1apt-group5actor · 1
Malware asociado
elf.greedyantd
Tecnicas MITRE
T1059.003, T1210, T1566.001, T1071.001
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
14
Actualizado
Wed, 01 Ju

Sectores objetivo (SOCRadar)

Data Processing, Hosting, and Related Services