Anonymous 64, also tracked as APT-C-64 and written as Anonymous64 or Anonymous_64, is an alleged Taiwan-linked intrusion and influence-oriented group publicly accused by Chinese authorities of operating in support of Taiwan’s Information, Communications and Electronic Force Command. Available reporting ties the group to long-running activity directed at targets in mainland China, with claimed operations dating back to 2006. The attribution is politically charged and rests primarily on Chinese government and affiliated security-organization allegations; however, the actor name is consistently associated with website compromise activity and attempts to manipulate public-facing information systems. The group is described as focusing on the compromise of websites and other broadcast or display platforms, including digital signage and television stations, with the apparent objective of displaying politically themed or unauthorized content. This places Anonymous 64 closer to a defacement and messaging-oriented actor than to a conventional espionage cluster centered on covert collection. Chinese reporting also characterizes the group as having targeted Chinese online assets in ways aligned with pro-Taiwan independence narratives. Reported tradecraft includes attempts to infiltrate internet-facing systems through exploitation of known vulnerabilities and use of broadly available tools and techniques rather than bespoke malware or zero-day capabilities. The same reporting portrays the actor as having weak operational security and limited anti-forensics, with some operations allegedly detected by defensive monitoring and honeypots. High-confidence public details do not establish a distinctive malware family set for Anonymous 64, nor do they substantiate ransomware or financially motivated operations. Known aliases include APT-C-64, Anonymous 64, Anonymous64, and Anonymous_64. Based on the available information, the actor is best characterized as an alleged Taiwan-linked, politically motivated intrusion group focused on website compromise and public-message disruption against Chinese targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of five Taiwan-attributed APT groups (per CVERC claim) alleged to conduct cyber espionage against mainland China entities.
Attempted to compromise websites, allegedly operated by Taiwan's Information, Communications and Electronic Force Command with U.S. assistance.
APT-C-64 is accused of infiltrating websites, digital signage, and TV stations to display illegal content, but is described as ineffective and often caught by honeypots.
Hacktivist group alleged by China’s MSS to have ties to the Taiwanese government and to conduct hacking activity against mainland China, Hong Kong, and Macau; discussed as part of China’s naming-and-shaming campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.