A resourceful cyber-espionage actor targeting Kazakh government and dissidents, known for custom malware and commercial spyware.
Analyst brief
APT-C-34 (Golden Falcon) is a resourceful cyber-espionage actor primarily targeting Kazakhstan. Their victims include government agencies, military, diplomats, researchers, journalists, private companies, education, religious figures, and dissidents. They leverage custom-built malware and expensive commercial spyware for operations. Defenders should prioritize monitoring for targeted phishing, anomalous dual-use tooling, and unusual network behaviors affecting governmental and diplomatic entities.
APT-C-34
Golden Falcon
unknown
As reported by ZDNet, Chinese cyber-security vendor Qihoo 360 published a report on 2019-11-29 exposing an extensive hacking operation targeting the country of Kazakhstan. Targets included individuals and organizations involving all walks of life, such as government agencies, military personnel, foreign diplomats, researchers, journalists, private companies, the educational sector, religious figures, government dissidents, and foreign diplomats alike. The campaign, Qihoo 360 said, was broad, and appears to have been carried by a threat actor with considerable resources, and one who had the ability to develop their private hacking tools, buy expensive spyware off the surveillance market, and even invest in radio communications interception hardware.
Which country does APT-C-34 (Golden Falcon) primarily target?+
APT-C-34 primarily targets Kazakhstan.
Which sectors and individuals does this group target?+
Targets include government agencies, military personnel, diplomats, researchers, journalists, private companies, the education sector, religious figures, and dissidents.