BlueHornet (APT49) targets government entities, exfiltrates region-specific data, and compromises other APT groups.
Analyst brief
BlueHornet (APT49, AgainstTheWest) is a threat actor of unknown type targeting government entities in China, North Korea, Iran, and Russia. Their key TTPs include exfiltration of region-specific data, selling it on the dark web, and compromising other APT groups like Lazarus Group; they recently disclosed a zero-day exploit in NGINX 1.18. Defenders should urgently patch web servers, especially NGINX instances, monitor for unauthorized access to sensitive government data, and utilize dark web monitoring to assess potential leaks.
BlueHornet
APT49AgainstTheWest
unknown
BlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia. They have compromised and leaked data from other APT groups like Kryptonite Panda and Lazarus Group. BlueHornet has been involved in campaigns such as Operation Renminbi, Operation Ruble, and Operation EUSec, focusing on exfiltrating region-specific data and selling it on the dark web. They have also been known to collaborate with different threat actors and have recently disclosed a zero-day exploit in NGINX 1.18.