TEMP.Jumper, also known as TEMP.Periscope, Leviathan, APT40, and several other aliases, is a China-nexus cyber espionage group. This threat actor has been active in the cybersecurity landscape for years, targeting government organizations, private businesses, and universities worldwide. Notably, between 2011 and 2018, the group carried out numerous hacking operations, leading to the U.S. Justice Department indicting four of its members in July 2021.
The group's activities have drawn international attention, with cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the UK, and the US issuing a joint advisory warning about APT40. The warning highlighted the group's capability to rapidly exploit disclosed flaws, indicating a high level of sophistication and agility in their operations. This aligns with the observed tactics, techniques, and procedures (TTPs) of TEMP.Jumper, which overlap significantly with those of TEMP.Periscope and public reporting on "NanHaiShu."
In terms of malware usage, TEMP.Periscope has leveraged a relatively large library of tools shared with multiple other suspected Chinese groups. One such tool is AIRBREAK, a JavaScript-based backdoor also reported as "Orz" that retrieves commands from hidden strings in compromised webpages and actor-controlled profiles on legitimate services. This suggests an advanced operational capacity and underscores the necessity for robust cybersecurity measures to mitigate threats posed by this group.
Description last updated: 2024-07-10T18:15:51.936Z