CopperTurtle is an advanced persistent threat group associated with operations in East Asia. Reported activity shows the group using HTTPS for command and control, including downloading backdoors through traffic masquerading as legitimate software activity. CopperTurtle appears in reporting on modern Asian APT tradecraft that emphasizes stealthy post-compromise operations and long-term access rather than disruptive effects. Observed behavior attributed to CopperTurtle and the broader operational patterns in which it is referenced include credential access, host and network discovery, lateral movement, collection, and covert command-and-control. The surrounding tradecraft includes use of native Windows utilities and administrative mechanisms, credential dumping from local and domain sources, searches for exposed credentials in enterprise shares and user files, browser credential theft, remote execution through common Windows management channels, and movement across SMB-accessible systems. The group is also associated with defense-evasion practices such as masquerading and blending malicious traffic with normal encrypted web communications. CopperTurtle is best characterized as a cyber-espionage actor operating within the East Asian APT ecosystem. High-confidence public characterization supports its use of HTTPS-based C2 and broader intrusion behaviors consistent with reconnaissance, credential theft, persistence, lateral movement, post-exploitation, and data collection for intelligence purposes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as saving SAM and SYSTEM hives to dump credentials from the Security Account Manager.
Uses HTTPS-based C2 and downloads backdoors, then sends victim information and receives commands from C2.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.