Poison Carp

Threat Actor updated 19 days ago (2024-08-19T21:17:42.352Z)
Download STIX
Preview STIX
Poison Carp, also known as Insomnia, is a threat actor linked to Chinese state-sponsored hacking groups. It has been implicated in various malicious activities, including spyware campaigns against Tibetan minorities. The group's activities were brought to light through analysis of leaked data from iSoon, a Chinese hack-for-hire contractor. Researchers at Recorded Future found documents linking iSoon to Poison Carp, along with other Chinese state hacking groups tracked as RedHotel and RedAlpha. In 2019, the digital rights organization Citizen Lab attributed an attack to Poison Carp. This was based on evidence that included shared IP addresses and references to an Android remote access Trojan previously linked to the group. An IP address found in the iSoon leak was identified as hosting a phishing site used against Tibetans in a hacking campaign in 2019. At the time, Citizen Lab researchers named the hacking group "Poison Carp." The findings suggest that Poison Carp operates alongside RedHotel, RedAlpha, and other Chinese state-sponsored groups, indicating a complex and interconnected landscape of cyber threats. The group's past activities and its association with other high-profile threat actors underscore the significant risk it poses to cybersecurity. Its connection to state-sponsored activities further highlights the geopolitical implications of its operations.
Description last updated: 2024-08-19T21:16:46.145Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Apt
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Poison Carp Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
BankInfoSecurity
19 days ago
Chinese Hacking Firm iSoon Targeted European Networks
CERT-EU
7 months ago
New Leak Shows Business Side of China’s APT Menace – GIXtools
Krebs on Security
7 months ago
New Leak Shows Business Side of China’s APT Menace
CERT-EU
6 months ago
Spyware leak offers 'first-of-its-kind' look inside Chinese government hacking efforts | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
Unit42
6 months ago
Data From Chinese Security Services Company i-Soon Linked to Previous Chinese APT Campaigns
BankInfoSecurity
5 months ago
iSoon Leak Shows Links to Chinese APT Groups