Full Report
The FishMonger APT Group has been linked with I-SOON, targeting governments, NGOs and think tanks in cyber-espionage campaigns
Analysis Summary
# Threat Actor: FishMonger APT Group
## Attribution & Identity
* **Primary Attribution:** Chinese cyber-espionage group.
* **Known Association:** Believed to be an operational arm of the technology contractor **I-SOON**, which was recently indicted by the US Department of Justice.
* **Aliases:** Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10.
* **Operational Context:** Operates under the **Winnti Group** umbrella.
* **Locality:** Believed to primarily operate out of Chengdu, China.
## Activity Summary
FishMonger has a history of cyber-espionage dating back to at least 2019. The actor was responsible for **Operation FishMedley** in 2022, a cyber campaign that successfully compromised seven organizations globally.
## Tactics, Techniques & Procedures
- Deployment of sophisticated malware implants.
- Utilize tools commonly associated with China-aligned threat actors.
- **Malware Families Used:** ShadowPad, Spyder, SodaMaster.
## Targeting
* **Sectors:** Government agencies, Non-Governmental Organizations (NGOs), charities, geopolitical think tanks, and religious organizations.
* **Geography:** Asia, Europe, and the United States.
* **Victims (Operation FishMedley Example):**
* Government agencies in Taiwan and Thailand.
* NGOs and charities in the US and Asia.
* A Catholic organization in Hungary.
* A geopolitical think tank in France.
## Tools & Infrastructure
* **Malware Families Used:** ShadowPad, Spyder, SodaMaster.
* **Infrastructure:** General use of tools associated with China-aligned threat actors (specific C2/IPs not provided in the text).
## Implications
FishMonger represents a persistent, state-sponsored cyber-espionage threat, evidenced by its direct structural link to I-SOON and its history of targeting sensitive governmental and non-profit entities across key diplomatic and geopolitical regions (US, Asia, Europe).
## Mitigations
* Implement enhanced detection and monitoring for malware families commonly used by APTs operating under the Winnti umbrella, such as ShadowPad, Spyder, and SodaMaster.
* Prioritize supply chain risk management concerning third-party technology contractors, given the actor's association with I-SOON.
* Strengthen defenses targeting specific high-value sectors mentioned: governmental entities, NGOs, and geopolitical research institutions.