APT26
APT26 is a China-linked cyberespionage threat actor also referred to in the provided content as Taffeta Typhoon, Turbine Panda, BearClaw, JerseyMikes, Red Kobold, Technetium, and TG-0055. The content links APT26 to the Jiangsu Province Ministry of State Security / Jiangsu MSS Bureau, including a 2018 U.S. indictment and a 2019 CrowdStrike report. It describes the group as conducting cyberespionage, including operations from 2010 to 2015 against companies supplying COMAC C919 components and against U.S. and European jet-engine manufacturers, with the apparent objective of stealing commercial and aerospace trade-secret information to benefit China’s state-owned aerospace sector. The content specifically notes targeting aligned with Jiangsu’s aerospace industry priorities. Tradecraft directly mentioned in the content includes use of malware/tooling associated with the keywords "hide" and "install."
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted cyberespionage against aerospace companies supplying components for COMAC’s C919 program.
APT26 is known for cyber intrusions and intellectual property theft, particularly targeting aerospace and jet engine manufacturers in the US and Europe, supporting China's domestic aerospace industry, especially the C919 airliner project.
Listed as a China-linked APT group; no additional operational detail provided in the content beyond inclusion in an APT group list.
China-linked espionage actor referenced as associated with the Jiangsu MSS branch and described as focused on online intellectual property theft; also discussed in the context of MSS using MPS cover/co-location for operations.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.