Uptime Hamster: 10d 8h 6mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza PassCV

PassCV

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: TG-3279, Winnti Umbrella, Sabre, Kitkiot, Conpee, Etso, Runxx, dnsenum, s (custom port scanner), rdp_crk, icmp_shell, Jynxkit, Gh0st RAT, NetCommander, Carberp RAT, otros, Gaming Companies, Winnti
Ver en IntelTracker → APTTrail →
PassCV, first documented in 2016, is an APT group assessed with high confidence to be of Chinese origin, primarily motivated by information theft and espionage. The group uniquely distinguishes itself by consistently leveraging a wide array of stolen Authenticode-signing certificates to sign their malicious payloads, which are predominantly delivered through spear-phishing campaigns utilizing phony resumes and curriculum vitae. Over time, PassCV has evolved its operational methodology, incorporating both older Remote Administration Tools and custom-developed malware into its attack repertoire. This group is also identified by the name PassCV (Blue Coat Systems).

Aliases del actor

TG-3279Winnti UmbrellaSabreKitkiotConpeeEtsoRunxxdnsenums (custom port scanner)rdp_crkicmp_shellJynxkitGh0st RATNetCommanderCarberp RATotrosGaming CompaniesWinnti

Actores similares

gh0st-ratactor · 1madliberatorransomware · 2markiratactor · 1apt-goldenratactor · 1exileratactor · 1dimanoratactor · 1apt-packratactor · 1apt-spacepiratesactor · 1Data from Configuration Repositoryactor · 1Container Orchestration Jobactor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupduckduckgo.comPassCV (China)
DLS / leak siteupduckduckgo.comPassCV (China)
Motivacion