Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-09

Kapibala

As of 2026-09-22, Kapibala is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning apt, vulnerability. ATT&CK coverage spans 25 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1190 (Exploit Public-Facing Application), T1552.001 (Unsecured Credentials), T1005 (Data from Local System).

Tracked threats
22 critical
First seen
2026-09-21
Last seen
2026-09-22
ATT&CK techniques
25across 2 of 2 threats
Related CVEs
12Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 2 tracked threat(s) · Categories: APT, VULNERABILITY

Activity timeline

Kapibala appears in 2 tracked threats between and .

ATT&CK techniques observed

25 techniques observed across 2 of 2 tracked threats · Command and Control (4), Stealth (formerly Defense Evasion) (4), Collection (3), Credential Access (2), Discovery (2), Initial Access (2)
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
  • T1552.001 Unsecured Credentials — Credential Accessobserved in 2 of 2 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
  • T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1021.004 SSH — Lateral Movementobserved in 1 of 2 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1027.002 Software Packing — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1059.004 Unix Shell — Executionobserved in 1 of 2 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 1 of 2 tracked threats
  • T1071.002 File Transfer Protocols — Command and Controlobserved in 1 of 2 tracked threats
  • T1078.001 Default Accounts — Initial Accessobserved in 1 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1110.003 Password Spraying — Credential Accessobserved in 1 of 2 tracked threats
  • T1134.001 Token Impersonation/Theft — Privilege Escalationobserved in 1 of 2 tracked threats
  • T1136.001 Local Account — Persistenceobserved in 1 of 2 tracked threats

Tracked threats

Related CVEs

12 CVEs referenced by tracked Kapibala activity