Brass Typhoon is a prolific China-based cyber threat actor which has been active since at least 2012. The group performs dual operations of cyber espionage aligning with Chinese state interests and financially motivated activity. Atypically for China-based threat groups, Brass Typhoon employs advanced malware traditionally reserved for espionage purposes in attacks for financial gain. It is assessed with high confidence that the group is in part comprised of civilian contractors working on behalf of the Chinese government, and who share tools, infrastructure, and targets.
The Quorum Cyber Threat Intelligence team provides threat actor profiles so that you can better understand cybercriminals’ tactics, techniques, and procedures (TTPs).