The 8th Technical Reconnaissance Base (8th TRB), also identified as PLA Unit 61046, is a Chinese military cyber espionage organization assessed to operate within the PLA Cyberspace Force. Available reporting links it to activity commonly tracked as APT15, indicating either direct identity overlap or extremely close operational alignment. The group has been associated with intrusions against government entities, including military-related targets, and with broader targeting across multiple countries, with notable emphasis on Belt and Road-associated states in Africa and at least one documented Thai military victim. Observed tradecraft includes victim research, operational logging, mailbox review, credential collection, and post-compromise exploitation. Reported operator workflows include use of a Python-based exploit chain for CVE-2020-0688 to gain initial access to vulnerable servers, deployment of webshells for persistence and post-exploitation, and collection of credentials using tools such as Mimikatz and Impacket. The actor’s activity reflects a mature espionage-oriented intrusion lifecycle spanning reconnaissance, initial access, persistence, credential theft, and data collection from compromised government networks. The group has also been associated with infrastructure and tradecraft overlaps tied to APT15, including references to tooling and operational markers linked to that cluster. Reporting further notes references to internal sub-elements including a Second Division and a Third Section, suggesting a structured military organization. Overall, the 8th TRB is best characterized as a Chinese state cyber espionage actor focused on intelligence collection against government and defense-related targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.