APT-C-67, also referred to as Ursa, is an alleged Taiwan-linked advanced persistent threat cluster that Chinese state-affiliated reporting attributes to Taiwan’s Information, Communications and Electronic Force Command. The actor is described as part of a broader set of groups purportedly operating in support of Taiwanese cyber operations against China, with alleged backing from the United States. These claims are politically sensitive and derive from Chinese attribution reporting; independent corroboration is not available in the supplied facts. APT-C-67 is alleged to focus on compromising video surveillance devices and using that access to deploy malware and collect geographic intelligence. Reported tradecraft includes intrusion into exposed or vulnerable surveillance infrastructure, malware placement on compromised devices, and intelligence collection derived from those systems. In the broader reporting on the associated cluster set, the operators are characterized as relying primarily on known vulnerabilities, public or commercial tooling, and comparatively weak anti-tracing practices rather than zero-day exploitation or highly bespoke cyber capabilities. APT-C-67 is presented as one of five alleged ICEFCOM-affiliated groups, alongside APT-C-01, APT-C-62, APT-C-64, and APT-C-65. Within that grouping, APT-C-67 is specifically associated with surveillance-device compromise and geographic intelligence collection rather than website defacement, phishing-led intrusion, or critical-infrastructure surveillance missions attributed to the other named clusters.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT-C-67 is a Taiwan-linked APT group accused by China of cyber espionage, with a focus on collecting geographic intelligence from Chinese targets.
Attempted to compromise video surveillance devices, allegedly operated by Taiwan's Information, Communications and Electronic Force Command with U.S. assistance.
APT-C-67 is accused of targeting video surveillance devices to plant malware and gather geographic intelligence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.