GroupCC is a China-linked cyberespionage threat cluster assessed to be related to APT41 and likely part of its broader operational ecosystem. It has been identified through code similarities, shared Cobalt Strike metadata, and overlapping tradecraft with other APT41-associated subgroups, including Earth Longzhi and Earth Baku. GroupCC is known for using customized Cobalt Strike loader development patterns and operational infrastructure concealment techniques associated with APT41-linked activity. Observed tradecraft tied to GroupCC includes custom malware loading and decryption routines, process injection, and command-and-control masking through content delivery network infrastructure. GroupCC has also been linked by code similarity to loader families used in APT41 subgroup operations, including shared decryption logic and related implementation patterns. Its activity is consistent with post-compromise intrusion operations focused on stealth, persistence, and follow-on exploitation rather than commodity cybercrime or ransomware. GroupCC is best understood as an APT41-related subgroup or closely aligned cluster operating within a Chinese cyberespionage context. High-confidence reporting in the available facts supports its relationship to APT41-linked operations, but does not independently establish a fuller victimology or a distinct campaign history for GroupCC beyond those overlaps.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an APT41-related activity cluster previously observed using Fastly CDN to obscure C2 infrastructure, similar to infrastructure-hiding observed in this report.
A group believed to be an APT41 subgroup that shares Cobalt Strike metadata, loader decryption routines, and Fastly CDN-based C2 concealment tradecraft with Earth Longzhi.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.