APT-C-62, also known as Viola Tricolor, is an alleged advanced persistent threat cluster publicly attributed by Chinese state-affiliated reporting to Taiwan’s Information, Communications and Electronic Force Command. The actor is described as one of several Taiwan-linked groups said to have operated in the context of cross-strait cyber operations following Taiwan’s 2016 political transition. High-confidence reporting in the available material attributes APT-C-62 with phishing-led intrusions against government and scientific organizations in China. The group is described as using phishing for initial access, followed by malware deployment on victim systems and data exfiltration. The same reporting states that APT-C-62’s activity overlapped with that of APT-C-01, another alleged Taiwan-linked cluster, in both targeting and tradecraft. The available material further states that Chinese reporting characterized APT-C-62 and related clusters as comparatively low capability, alleging reliance on known vulnerabilities, public or commercial tooling, and weak anti-tracing practices rather than zero-day development or highly sophisticated operational security. Those capability assessments are claims made within the attribution narrative and should be treated as allegations rather than independently corroborated technical consensus. Known aliases include Viola Tricolor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of five Taiwan-attributed APT groups (per CVERC claim) alleged to conduct cyber espionage against mainland China entities.
Targeting government and scientific organizations, allegedly operated by Taiwan's Information, Communications and Electronic Force Command with U.S. assistance.
APT-C-62 is accused of using phishing to attack government and scientific targets, installing malware, and exfiltrating data. Some tactics are also used by APT-C-65.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.