SLIME86 is a China-nexus advanced persistent threat actor associated with intrusion activity that leverages trusted-provider compromise to reach downstream victims. The group has been identified breaching upstream providers and then pivoting into customer environments, including government, military, and critical infrastructure networks. This operating pattern aligns with supply-chain and service-provider intrusion tradecraft designed to inherit access and trust relationships rather than relying solely on direct compromise of end targets. The actor has been linked to campaigns targeting network edge infrastructure such as firewalls, routers, and VPN appliances through exploitation of critical vulnerabilities. China-nexus operators in this activity cluster have used device-family-specific backdoors intended to maintain durable access on edge devices, including persistence that can survive reboots and in some cases outlast patching or firmware updates. The broader tradecraft associated with these operations also includes use of relay infrastructure built from compromised IoT and NAS devices to obscure origin and support covert data movement. SLIME86 is assessed to primarily support espionage objectives. Reported victimology includes public-sector, military, and critical-infrastructure entities. No high-confidence ransomware or extortion activity is established for this actor from the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.