SLIME88

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:29:59

Targeted industries: manufacturing technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:us country_code:kr country_code:in country_code:fr country_code:tw

Context

SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices and establishing an ORB network tracked as GOBLIN14. The group has targeted IT and manufacturing entities in the US, South Korea, India, and France. Additionally, SLIME88 has aimed at Taiwan’s energy sector using phishing emails and fake certificate installers to deploy backdoor programs like AdaptixC2 and CobaltStrike. They often utilize Cloudflare to obscure their C2 IP addresses, evading detection.

Exploited vulnerabilities

  • CVE-2026-34197 (vulnerability)

Reports & references

  • teamt5.org — Alert Exploitation Of Cve 2026 34197 In Apache Active Mq (report)

External references