TaskMasters is a suspected Chinese state-sponsored APT group targeting industrial and government sectors in Russia and the CIS.
Analyst brief
TaskMasters (also known as BlueTraveller) is a suspected Chinese state-sponsored APT group active since at least 2010, primarily targeting industrial, energy, and government sectors in Russia and the CIS. The group utilizes a diverse toolkit, notably the Webdav-O Trojan which bypasses network defenses by connecting to legitimate services, and the BackDoor.RemShell.24 malware. They have been linked to high-profile operations, potentially alongside TA428, including attacks against Russian federal executive authorities in 2020. Defenders should focus on detecting unusual legitimate service abuse for C2, covert communication channels, and targeted spear-phishing campaigns aimed at government and critical infrastructure entities in the specified geopolitical context.
TaskMasters
BlueTraveller
unknown
TaskMasters is a state-sponsored Chinese APT that has been active since at least 2010, primarily targeting industrial, energy, and government sectors in Russia and the CIS. The group has been linked to the Webdav-O Trojan, which employs techniques to bypass network defenses by connecting to legitimate services. Investigations suggest that TaskMasters may have been involved in attacks against Russian federal executive authorities in 2020, potentially alongside another Chinese group, TA428. Additionally, the group has been associated with the BackDoor.RemShell.24 malware, indicating a diverse toolkit in their operations.
Which regions and sectors are typically targeted by the TaskMasters APT group?+
TaskMasters targets the industrial, energy, and government sectors in Russia and the CIS.
What specific TTPs should defenders focus on regarding the TaskMasters group?+
Defenders should focus on detecting unusual legitimate service abuse for C2, covert communication channels, and targeted spear-phishing campaigns aimed at government entities in the specified geopolitical context.