Teleboyi — APT Profile
Teleboyi deploys the PlugX RAT and is reportedly based in China. TeamT5 identified a custom PlugX loader used by Teleboyi that employs a similar string decryption algorithm as seen in the McUtil.dll loader from Operation Harvest. While there are weak links to the dsqurey[.]com domain, the connection remains uncertain due to the domain's registration history.Tools & malware
- AsyncRAT rat
- China Chopper webshell
- Cobalt Strike offensive-security-tool
- DeedRAT rat
- DoubleShell backdoor
- FakeWorker malware
- Godzilla webshell
- LibreCoin (RatelS) backdoor
- PlugX backdoor
- ShadowPad backdoor
- Sliver offensive-security-tool
- TripleZero (Mélofée) backdoor
- Winnti backdoor