Nexus APT
Nexus Zeta · TAG-63 · Gallium
Nexus APT is a sophisticated cyber espionage group believed to have been active since at least 2012. The group has demonstrated advanced persistent threat capabilities with a focus on long-term intelligence gathering operations targeting telecommunications providers, government entities, and technology companies across Southeast Asia, Europe, and Africa. Their operations show a high degree of operational security and the use of custom-developed malware frameworks. The threat actor is characterized by their patient reconnaissance activities, often maintaining access to compromised networks for extended periods before conducting data exfiltration. Nexus APT demonstrates extensive knowledge of network architectures and shows particular interest in telecommunications infrastructure, likely to enable further intelligence collection capabilities. Their campaigns have shown increasing sophistication over time, incorporating supply chain compromises and living-off-the-land techniques to evade detection. Nexus APT's infrastructure demonstrates careful compartmentalization and the use of compromised legitimate infrastructure to blend their command-and-control traffic with normal network activity. The group has been observed using both custom malware and publicly available tools, adapting their tactics based on the target environment.