TaskMasters

Aliases: BlueTraveller

First seen
2010-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:18:10

Targeted industries: government-and-public-sector energy-and-utilities defense-and-aerospace

Targeted regions: country_code:ru country_code:cn country_code:kz

Context

TaskMasters is a state-sponsored Chinese APT that has been active since at least 2010, primarily targeting industrial, energy, and government sectors in Russia and the CIS. The group has been linked to the Webdav-O Trojan, which employs techniques to bypass network defenses by connecting to legitimate services. Investigations suggest that TaskMasters may have been involved in attacks against Russian federal executive authorities in 2020, potentially alongside another Chinese group, TA428. Additionally, the group has been associated with the BackDoor.RemShell.24 malware, indicating a diverse toolkit in their operations.

Reports & references

  • group-ib.com — Task (report)
  • decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)

External references