APT-C-65, also referred to as Neon Pothos or Neon Porthos, is an alleged Taiwan-linked advanced persistent threat cluster that Chinese state-affiliated reporting attributes to Taiwan’s Information, Communications and Electronic Force Command. The group is described as focusing on cyber operations against Chinese critical infrastructure, particularly surveillance-oriented activity timed around periods of major talks involving United States or Taiwanese politicians. Reported tradecraft overlaps with that attributed to APT-C-62, including phishing-based intrusion activity, malware deployment, and follow-on data theft or surveillance. Chinese reporting further characterizes the group as relying primarily on known vulnerabilities, publicly available tools and techniques, and comparatively weak anti-tracing practices rather than bespoke cyber weapons or zero-day exploitation. Within that reporting, APT-C-65 is presented as one of several affiliated clusters allegedly operating in support of Taiwan’s broader cyber objectives against China. Attribution, organizational structure, and capability assessments in this case rest on Chinese government-linked allegations and should therefore be treated with caution unless independently corroborated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT-C-65 is a Taiwan-linked APT group accused by China of cyber espionage against Chinese government and public sector targets.
Attempted to compromise critical infrastructure, allegedly operated by Taiwan's Information, Communications and Electronic Force Command with U.S. assistance.
APT-C-65 is accused of surveilling critical infrastructure, especially during major political events involving the US or Taiwan.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.