SLIME88 is a China-linked APT group known for exploiting critical Apache ActiveMQ vulnerabilities to target IT and manufacturing sectors.
Analyst brief
SLIME88 is an APT group assessed to have a China nexus. It primarily targets IT and manufacturing sectors in the US, South Korea, India, and France, as well as Taiwan's energy sector. The group exploits the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy the SoxAgent RAT, establishing an ORB network tracked as GOBLIN14, while also using phishing emails and fake certificate installers to deliver backdoors like AdaptixC2 and CobaltStrike. Defenders should prioritize patching Apache ActiveMQ systems and monitoring network traffic for C2 infrastructure obscured by Cloudflare.
SLIME88
unknown
SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices and establishing an ORB network tracked as GOBLIN14. The group has targeted IT and manufacturing entities in the US, South Korea, India, and France. Additionally, SLIME88 has aimed at Taiwan’s energy sector using phishing emails and fake certificate installers to deploy backdoor programs like AdaptixC2 and CobaltStrike. They often utilize Cloudflare to obscure their C2 IP addresses, evading detection.