# DarkSpectre

> As of 2026-07-11, DarkSpectre is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. ATT&CK coverage spans 48 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1008 (Fallback Channels), T1027 (Obfuscated Files or Information).

- **Nation:** China
- **Tracked threats:** 2
- **Categories:** MALWARE
- **As of:** 2026-07-11

## ATT&CK techniques observed

48 techniques observed across 2 of 2 tracked threats. Tactics: Command and Control (10), Stealth (formerly Defense Evasion) (8), Credential Access (6), Resource Development (5), Initial Access (4), Collection (3).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1008](https://intel.threadlinqs.com/technique/T1008) Fallback Channels — Command and Control — observed in 2 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 2 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 2 tracked threats
- [T1111](https://intel.threadlinqs.com/technique/T1111) Multi-Factor Authentication Interception — Credential Access — observed in 2 of 2 tracked threats
- [T1176](https://intel.threadlinqs.com/technique/T1176) Software Extensions — Persistence — observed in 2 of 2 tracked threats
- [T1185](https://intel.threadlinqs.com/technique/T1185) Browser Session Hijacking — Collection — observed in 2 of 2 tracked threats
- [T1189](https://intel.threadlinqs.com/technique/T1189) Drive-by Compromise — Initial Access — observed in 2 of 2 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 2 of 2 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 2 of 2 tracked threats
- [T1001.002](https://attack.mitre.org/techniques/T1001/002/) Steganography — Command and Control — observed in 1 of 2 tracked threats
- [T1027.003](https://intel.threadlinqs.com/technique/T1027.003) Steganography — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1027.013](https://intel.threadlinqs.com/technique/T1027.013) Encrypted/Encoded File — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats

## Tracked threats

- [StegoAd Campaign: 119 Malicious Edge Extensions Hid Malware in Images, Fonts, and Config Files, Up to 2.6M Installs](https://intel.threadlinqs.com/threat/TL-2026-1221) — HIGH
- [StegoAd Campaign: 119 Malicious Microsoft Edge Extensions Deliver Steganographic Malware to 2.6M Users](https://intel.threadlinqs.com/threat/TL-2026-1207) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/DarkSpectre
