APT26, also known as Taffeta Typhoon, Turbine Panda, JerseyMikes, Red Kobold, Technetium, TG-0055, Shell Crew, WebMasters, KungFu Kittens, Group 13, PinkPanther, and Bronze Express, is a China-linked cyber-espionage threat actor associated with the Jiangsu provincial apparatus of the Ministry of State Security. Public reporting and indictments have linked the group to the Jiangsu State Security Department and to long-running theft of commercial and technical information in support of Chinese state interests. APT26 is best known for espionage operations targeting aerospace and aviation-related organizations, including companies involved in jet-engine technology and suppliers connected to the COMAC C919 program. Activity attributed to the group has focused on stealing intellectual property and sensitive commercial information from U.S. and European firms, particularly between 2010 and 2015. The actor’s targeting aligns with Jiangsu’s aerospace industrial priorities and broader Chinese efforts to accelerate domestic high-technology development. Tradecraft associated with APT26 and comparable Chinese espionage clusters includes initial access through spearphishing attachments and exploitation of public-facing applications, followed by persistence via Windows services, scheduled tasks, and DLL side-loading. The group has been associated with process hollowing, PowerShell-based execution, use of SSH tunneling and common administrative utilities for pivoting and exfiltration, SMB-enabled lateral movement, credential dumping, and sustained command-and-control over HTTP and HTTPS. Operations emphasize long-term access, internal reconnaissance, collection, and exfiltration rather than disruptive effects. APT26 is assessed primarily as a state-sponsored espionage actor focused on theft of intellectual property, commercial secrets, and strategic technical data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted cyberespionage against aerospace companies supplying components for COMAC’s C919 program.
APT26 is known for cyber intrusions and intellectual property theft, particularly targeting aerospace and jet engine manufacturers in the US and Europe, supporting China's domestic aerospace industry, especially the C919 airliner project.
Listed as a China-linked APT group; no additional operational detail provided in the content beyond inclusion in an APT group list.
China-linked espionage actor referenced as associated with the Jiangsu MSS branch and described as focused on online intellectual property theft; also discussed in the context of MSS using MPS cover/co-location for operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.