SLIME88 is a China-nexus advanced persistent threat group that has compromised Linux systems to construct an operational relay box (ORB) network. Its documented victims include information technology and manufacturing organizations in the United States, as well as entities in South Korea, India, and France. An associated ORB network is temporarily tracked as GOBLIN14; this designation identifies the relay infrastructure rather than a separate actor or subgroup. Activity observed from April 7, 2026, involved exploitation of CVE-2026-34197, a remote code execution vulnerability in Apache ActiveMQ, followed by deployment of the SoxAgent Linux backdoor and remote access trojan. The exploitation mechanism uses crafted requests to the Jolokia API to cause the broker to retrieve a malicious remote XML configuration. The vulnerability ordinarily requires authentication, although default credentials or authentication bypass through CVE-2024-32114 can expose affected deployments. SLIME88 uses SoxAgent to convert compromised hosts into SOCKS5 relay nodes. The malware maintains a reverse command-and-control connection, dynamically negotiates AES-encrypted tunnels, and forwards TCP traffic through victim systems to conceal the operator's origin. It also supports remote updates, self-deletion, and heartbeat reporting with falsified tunnel metrics.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploiting CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent on Linux systems and build an ORB network.
A China-nexus threat group exploiting Apache ActiveMQ CVE-2026-34197 since at least April 7, 2026, and deploying SoxAgent on Linux hosts to build an operational relay box (ORB) network. Reported victims include US IT and manufacturing entities and organizations in South Korea, India, and France. The content also describes earlier targeting of Taiwan's energy sector through phishing and fake certificate installers. GOBLIN14 names the resulting ORB network, not a separately identified threat actor group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.