Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
Log → SplunkLog → Sentinel
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckLog → SplunkLog → SentinelAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

All Threat Actors

Nexus APT

Also known as: Nexus Zeta, TAG-63, Gallium

ActiveAdvancedEast Asia (suspected state-nexus)

Profile generated with AI assistance — review before citing.

0Campaigns
34Techniques
10IOCs
14Tools
0Matches
7Infrastructure
OverviewTechniquesToolsIOCsInfrastructureReferences

Overview

Nexus APT is a sophisticated cyber espionage group believed to have been active since at least 2012. The group has demonstrated advanced persistent threat capabilities with a focus on long-term intelligence gathering operations targeting telecommunications providers, government entities, and technology companies across Southeast Asia, Europe, and Africa. Their operations show a high degree of operational security and the use of custom-developed malware frameworks. The threat actor is characterized by their patient reconnaissance activities, often maintaining access to compromised networks for extended periods before conducting data exfiltration. Nexus APT demonstrates extensive knowledge of network architectures and shows particular interest in telecommunications infrastructure, likely to enable further intelligence collection capabilities. Their campaigns have shown increasing sophistication over time, incorporating supply chain compromises and living-off-the-land techniques to evade detection. Nexus APT's infrastructure demonstrates careful compartmentalization and the use of compromised legitimate infrastructure to blend their command-and-control traffic with normal network activity. The group has been observed using both custom malware and publicly available tools, adapting their tactics based on the target environment.

Motivations

EspionageIntelligence gatheringTelecommunications infrastructure compromiseStrategic information theftTechnology sector targeting

Target Sectors

Telecommunications providersGovernment entitiesTechnology sectorManaged service providersDefense contractorsFinancial institutionsThink tanksLegal firmsEducational institutions

Activity Timeline

First Seen

Jan 2012

Last Seen

Sep 2024

Quick Facts

OriginEast Asia (suspected state-nexus)
Sophisticationadvanced
StatusActive

MITRE ATT&CK Techniques

(34)

Initial Access

T1078

Valid Accounts

Use legitimate credentials to authenticate and gain access.

T1190

Exploit Public-Facing Application

Exploit vulnerabilities in internet-facing applications to gain access.

T1133

External Remote Services

Abuse remote services like VPNs or RDP to gain access to the network.

Other

T1078.004

T1078.004

T1071.001

T1071.001

T1071.004

T1071.004

T1573.001

T1573.001

T1027.002

T1027.002

T1053.005

T1053.005

T1012

T1012

T1069

T1069

T1057

T1057

T1033

T1033

T1049

T1049

T1217

T1217

T1114.002

T1114.002

T1039

T1039

T1560.001

T1560.001

T1048.003

T1048.003

T1070.004

T1070.004

T1070.006

T1070.006

T1562.001

T1562.001

T1136.001

T1136.001

Defense Evasion

T1027

Obfuscated Files or Information

Encrypt, encode, or obfuscate payloads and data to evade detection.

T1055

Process Injection

Inject code into running processes to evade defenses and elevate privileges.

Execution

T1059.001

PowerShell

Use PowerShell commands and scripts for execution and automation.

T1059.003

Windows Command Shell

Use cmd.exe to execute commands and batch scripts.

Discovery

T1082

System Information Discovery

Collect OS version, architecture, hostname, and other system details.

T1083

File and Directory Discovery

Enumerate files and directories to find sensitive data or binaries.

T1087

Account Discovery

Enumerate local, domain, or cloud accounts on a system or environment.

T1018

Remote System Discovery

Discover remote systems on the network for lateral movement targets.

Collection

T1005

Data from Local System

Collect sensitive data stored on the local file system.

Exfiltration

T1041

Exfiltration Over C2 Channel

Exfiltrate stolen data over the existing command and control channel.

Persistence

T1547.001

Registry Run Keys / Startup Folder

Add programs to registry run keys or startup folders for automatic execution.

Tools & Malware

(14)

Custom webshells

malwareMalicious

Malware used by Nexus APT.

PingPull backdoor

malwareMalicious

Malware used by Nexus APT.

SoftEther VPN

malwareMalicious

Malware used by Nexus APT.

Mimikatz

legitimate toolLegitimate

Legitimate tool used by Nexus APT.

PsExec

legitimate toolLegitimate

Legitimate tool used by Nexus APT.

Cobalt Strike

frameworkLegitimate

Legitimate tool used by Nexus APT.

China Chopper webshell

malwareMalicious

Malware used by Nexus APT.

Custom RATs

malwareMalicious

Malware used by Nexus APT.

WinRAR for compression

malwareMalicious

Malware used by Nexus APT.

Custom loaders

malwareMalicious

Malware used by Nexus APT.

PowerShell Empire

malwareMalicious

Malware used by Nexus APT.

Custom credential dumpers

malwareMalicious

Malware used by Nexus APT.

Port scanners

malwareMalicious

Malware used by Nexus APT.

Network enumeration tools

malwareMalicious

Malware used by Nexus APT.

Indicators of Compromise

(10)
IOC values are defanged for safety
TypeValueNotes
domainowa365-management[.]comC2 domain mimicking Microsoft 365 infrastructure
domainlogin-microsoftonline[.]comPhishing and C2 infrastructure domain
domainwebmail-security[.]netCommand and control domain targeting webmail services
ip45[.]32[.]13[.]180Known C2 server IP address
ip107[.]191[.]62[.]45Infrastructure IP used for data exfiltration
hash3c1c2b9c8e7f4d6a5b8e9f0d1a2c3e4f5b6a7c8d9e0f1a2b3c4d5e6f7a8b9c0dSHA256 hash of PingPull backdoor variant
hash7f8e9d0c1b2a3f4e5d6c7b8a9f0e1d2c3b4a5f6e7d8c9b0a1f2e3d4c5b6a7f8eSHA256 hash of custom webshell loader
hash5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6bSHA256 hash of credential dumping tool
urlhxxps[://]owa365-management[[.]]com/api/auth/validateC2 callback URL mimicking legitimate authentication endpoint
domaincdn-content-delivery[.]netData exfiltration domain disguised as CDN service

Infrastructure

(7)
Domain values are defanged for safety
Domain / HostTypeStatusLast Checked
owa365-management[.]com

Command and control domain mimicking Microsoft Office 365 services

c2unknown—
login-microsoftonline[.]com

Phishing infrastructure impersonating Microsoft login portal

domainunknown—
webmail-security[.]net

C2 domain used for webmail targeting operations

c2unknown—
cdn-content-delivery[.]net

Data exfiltration infrastructure disguised as content delivery network

domainunknown—
45[.]32[.]13[.]180

VPS-hosted C2 server for lateral movement operations

ipunknown—
107[.]191[.]62[.]45

Data staging and exfiltration server

ipunknown—
hxxps

C2 callback URL mimicking legitimate authentication endpoint

domainunknown—

Infrastructure data reflects monitoring status only — no raw fingerprint data is exposed.

References

(6)

Microsoft Threat Intelligence: Gallium Targeting Global Telecom

https://www.microsoft.com/security/blog/2019/12/12/gallium-targeting-global-telecom/

CISA Alert: Advanced Persistent Threat Compromise of Government Agencies

https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a

Cybereason: Operation Soft Cell - A Worldwide Campaign Against Telecommunications Providers

https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers

Unit 42: PingPull Analysis and Infrastructure

https://unit42.paloaltonetworks.com/pingpull-gallium/

MITRE ATT&CK: Gallium

https://attack.mitre.org/groups/G0093/

CrowdStrike: Gallium Espionage Campaign

https://www.crowdstrike.com/blog/gallium-apt-group-targets-telecommunications/