Wekby

Threat Actor updated 4 months ago (2024-05-04T16:13:55.512Z)
Download STIX
Preview STIX
Wekby, also known as APT18, is a threat actor suspected to be based in China. This group has been actively involved in executing malicious activities for several years, targeting a wide range of sectors including Aerospace and Defense, Construction and Engineering, Education, Health and Biotechnology, High Tech, Telecommunications, and Transportation. Despite limited public information about this group, it's clear that their operations are extensive and sophisticated, posing a significant cybersecurity threat. The Wekby group employs advanced malware tied to the HTTPBrowser family, using DNS requests as a command and control mechanism. This approach aligns with previous iterations of HTTPBrowser, another malware family frequently utilized by Wekby. Their methods demonstrate a high level of technical expertise, indicating a well-resourced and capable adversary. The group continues to target various high-profile organizations, using their sophisticated malware to infiltrate systems and extract valuable information. Recently, an attack led by Wekby targeted a US-based organization. This incident underscores the group's ongoing activity and the persistent threat they pose to diverse industries such as healthcare, telecommunications, aerospace, defense, and high tech. Given the group's sophisticated tactics and broad target spectrum, it is crucial for organizations within these sectors to maintain robust cybersecurity measures and stay vigilant against potential threats.
Description last updated: 2023-11-29T00:32:51.261Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Wekby Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
Advanced Persistent Threats (APTs) | Threat Actors & Groups
MITRE
2 years ago
New Wekby Attacks Use DNS Requests As Command and Control Mechanism