Skip to main content

Threats Tagged 'auftime'

View all threats tagged with 'auftime'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: auftime

Threats Tagged 'auftime'

Click on any threat for detailed analysis and mitigation recommendations

APT31, a Chinese cyber espionage group, is actively targeting the Russian IT sector, especially government contractors, using advanced malware and stealthy tactics. They leverage cloud services for command and control, deploy new malware families like AufTime, COFFProxy, VtChatter, YaLeak, CloudyLoader, and OneDriveDoor, and use prepared scripts for lateral movement. Their operations are timed to exploit organizational workflows, such as holidays, enabling prolonged undetected presence. The group employs multiple persistence, credential access, and data exfiltration techniques, evolving their toolkit while retaining older tools to maintain stealth. Although primarily focused on Russia, the sophistication and targeting of government contractors pose risks to European organizations with similar profiles. Mitigation requires tailored detection of cloud-based C2, monitoring lateral movement scripts, and enhanced credential security. Countries with significant IT sectors supporting government contracts and geopolitical interest in Russia-China dynamics are most at risk. The threat is assessed as high severity due to its espionage nature, stealth, and potential for long-term data compromise without requiring user interaction or known exploits in the wild.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: auftime
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses