APT-C-34__2019__APT-C-34.cn.pdf
ID: 3067a426-5243-42f7-a6d0-a3ec638eba0c
STIX ID: report--3067a426-5243-42f7-a6d0-a3ec638eba0c
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2019-11-22
Last Modified Date: 2019-11-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
360 Core Security describes discovery of a previously unreported Russian‑language APT named Golden Falcon (APT‑C‑34) that conducts targeted espionage across Central Asia (primarily Kazakhstan). The group uses a mix of custom malware (Harpoon), modified legitimate remote‑access tools (TeamViewer/RMS hijacks), and purchased commercial surveillance tools (HackingTeam RCS v10.3.0 and NSO Pegasus), delivering implants via spear‑phishing, USB/offline installers and specialized radio/hardware intercept devices to exfiltrate sensitive government, research, media and diplomatic data.
