Tstark — APT Profile

TStark is the internal name Sophos X-Ops gave to a threat actor whose own cluster of devices it tracked during the Pacific Rim investigation into attacks on Sophos firewalls, published in October 2024. The name comes from the Proton Mail address used to register that cluster, which held some of the earliest payloads associated with the bookmark buffer overflow attack targeting CVE-2020-15069. Those devices showed telemetry consistent with intermittent VPN use, switching between IP addresses geolocated to Hong Kong and Chengdu. One physical device later registered to TStark had previously been registered by a former researcher at the University of Electronic Science and Technology of China in Chengdu. In mid-August 2020 Sophos obtained libxselinux.so, a customized userland rootkit built on code originally attributed to the Winnti group, directly from a TStark device. A week later it retrieved further files from a TStark device, among them malware built for Mac OS X and iOS and IFRAME injection code exploiting a WebAssembly vulnerability. Working with Volexity, Sophos assisted an organization supporting Tibetan exiles whose compromised device showed indicators overlapping both TStark's tooling and Evil Eye, a group Volexity attributed to multiple Chinese APT actors. Sophos retrospectively linked development of the bespoke rootkit libsophos.so, later found on victim devices, to TStark, after February 2022 shell history on two TStark devices showed the actor renaming and running it.

Tools & malware

Vendor research

Read the full analysis on IntelFusions