Threat reportAPTTL-2026-0082
ChainedShark APT (Actor240820): State-Sponsored Espionage Targeting Chinese Research Institutions via GrimResource & LinkedShell
ChainedShark APT (Actor240820) (TL-2026-0082) is a medium-severity advanced persistent threat campaign, first published 2026-02-13. It is attributed to ChainedShark with medium confidence, maps to 30 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 12 detection rules and 31 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 30MITRE ATT&CK
- Actors
- 1ChainedShark
- Detection rules
- 12SPL · KQL · Sigma
- IOCs
- 31Indicators of compromise
Key facts for TL-2026-0082
- Threat ID
- TL-2026-0082
- Severity
- MEDIUM
- Status
- MONITORING
- Category
- APT
- First published
- Last reviewed
- Attribution
- ChainedShark
- Attribution confidence
- MEDIUM
- Motivation
- ESPIONAGE
- Target sectors
- Education, Research, Government, Academia, Marine Technology, International Relations, Defense Research, Think Tanks
- Target regions
- China
- Detection rules
- 12
- Indicators of compromise
- 31
Malware and tooling in ChainedShark APT (Actor240820)
Malware and tooling: LinkedShell custom trojan — ChainedShark exclusive, high customization, advanced anti-forensic capabilities, LinkedShell custom trojan — high customization, advanced anti-forensic capabilities, first observed May 2024 in ChainedShark operations, LinkedShell — custom trojan with anti-forensic capabilities and high per-target customization (ChainedShark exclusive)
How ChainedShark APT (Actor240820) works
ChainedShark (Actor240820) is a state-sponsored APT group conducting espionage campaigns against Chinese university and research professionals specializing in international relations and marine technology, using GrimResource N-day exploitation and the custom LinkedShell trojan.
NSFOCUS Fuying Lab identified a state-sponsored threat actor designated Actor240820, codenamed ChainedShark, conducting persistent espionage campaigns against Chinese academic and research institutions since at least May 2024. The campaigns specifically target professionals in international relations and marine technology — two fields with direct geopolitical intelligence value for foreign state actors seeking insight into China's diplomatic positions and maritime capabilities. ChainedShark demonstrates state-level sophistication through multiple indicators: (1) Fluent Chinese-language social engineering using conference invitations and call-for-papers lures that convincingly mimic legitimate academic communications, (2) exploitation of the GrimResource N-day technique (disclosed by Elastic Security Labs in June 2024) to achieve code execution via specially crafted MSC (Microsoft Management Console) files, (3) deployment of LinkedShell, a custom trojan with advanced anti-forensic capabilities and high customization that has not been observed in any other threat actor's toolkit, (4) persistent targeting of the same individuals across multiple campaigns (May to November 2024), indicating dedicated intelligence collection requirements rather than opportunistic compromise. GrimResource exploits an old XSS vulnerability in apds.dll to execute JavaScript within the context of mmc.exe when a victim opens a crafted .msc file. The technique was initially disclosed by Elastic Security Labs and leverages DotNetToJScript for arbitrary code execution with minimal security warnings. ChainedShark's adoption of GrimResource within months of its public disclosure demonstrates rapid N-day weaponization capability — a hallmark of state-sponsored groups with dedicated vulnerability research teams. The LinkedShell trojan is purpose-built for long-term espionage: anti-forensic features hinder incident response, high customization allows per-target configuration, and the malware maintains persistent access for intelligence collection. The combination of academic targeting, Chinese-language fluency, marine technology focus, and diplomatic intelligence requirements suggests a state actor with specific geopolitical objectives related to the South China Sea, Taiwan Strait, or broader Indo-Pacific maritime disputes.
MITRE ATT&CK techniques used in TL-2026-0082
collection
T1005 Data from Local System; T1056 Input Capture; T1074 Data Staged; T1113 Screen Capture; T1114 Email Collection
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1202 Indirect Command Execution; T1218 System Binary Proxy Execution
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution; T1559 Inter-Process Communication; T1569 System Services
command-and-control
T1071 Application Layer Protocol; T1573 Encrypted Channel
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery
persistence
T1547 Boot or Logon Autostart Execution
initial-access
resource-development
T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains
defense-impairment
Remediation for ChainedShark APT (Actor240820)
Immediate actions
- Block inbound MSC files in email gateways and web filters
- Deploy ASR (Attack Surface Reduction) rules to restrict mmc.exe child process creation
- Monitor for mmc.exe spawning unexpected child processes (cmd.exe, powershell.exe, dllhost.exe)
- Alert on mmc.exe accessing apds.dll (file open event — not a library load)
- Brief targeted personnel (international relations, marine technology researchers) on conference invite phishing
Workarounds
- Rename or remove apds.dll if not required (breaks the GrimResource XSS chain)
- Use Group Policy to restrict MSC file execution from user-writable directories
- Deploy YARA rule from Elastic Security Labs for GrimResource MSC file detection
Longer-term hardening
- Implement application whitelisting to restrict mmc.exe execution to IT-approved contexts
- Deploy behavioral detection for DotNetToJScript execution patterns
- Monitor for creation of redirect[*] files in INetCache directory from mmc.exe
- Establish academic institution threat intelligence sharing for APT targeting awareness
- Restrict MSC file association to prevent user-initiated execution from email attachments
Weaknesses (CWE) in ChainedShark APT (Actor240820)
Timeline of ChainedShark APT (Actor240820)
- ChainedShark (Actor240820) conducts first observed campaign targeting Chinese university researchers in international relations with conference invitation lures. Custom LinkedShell trojan deployed. Source: NSFOCUS Fuying Lab
- First GrimResource sample uploaded to VirusTotal (SHA-256: 14bcb7196143fd2b800385e9b32cfacd837007b0face71a73b546b53310258bb). Initially attributed to DPRK actors by Genians. Source: https://www.elastic.co/security-labs/grimresource
- Elastic Security Labs publicly discloses GrimResource technique: XSS in apds.dll enables code execution via crafted MSC files in mmc.exe context. Provides detection rules and YARA signatures. Source: https://www.elastic.co/security-labs/grimresource
- ChainedShark adopts GrimResource N-day technique within weeks of public disclosure, incorporating it into attack chain targeting Chinese researchers. Demonstrates rapid weaponization capability. Source: NSFOCUS Fuying Lab
- NSFOCUS Fuying Lab designates the threat actor as Actor240820 based on first confirmed attribution date. Begins tracking persistent campaigns against Chinese academic institutions. Source: NSFOCUS Fuying Lab
- ChainedShark campaigns continue through November 2024, targeting the SAME individuals from May campaign. Persistent re-targeting over 6+ months indicates dedicated intelligence collection requirements and specific victim interest. Source: NSFOCUS Fuying Lab
- ChainedShark expands targeting to include Chinese marine technology researchers in addition to international relations academics. Marine technology targeting suggests intelligence requirements related to South China Sea, Taiwan Strait, or Indo-Pacific maritime capabilities. Source: NSFOCUS Fuying Lab
- ThreadLinqs Intelligence begins tracking as TL-2026-0082 after RSS detection. State-sponsored espionage targeting Chinese academic institutions via GrimResource + LinkedShell. Source: ThreadLinqs Intelligence
- NSFOCUS Fuying Lab publishes comprehensive analysis of ChainedShark (Actor240820) APT campaigns, LinkedShell trojan capabilities, and GrimResource exploitation chain. Source: NSFOCUS Fuying Lab
- As of 2026-05-29, ChainedShark (Actor240820) shows no campaign activity since Nov 2024; NSFOCUS's Feb 2026 retrospective is purely historical, with no takedown, attribution, rebrand, or successor reported. The actor is effectively dormant, yet its GrimResource apds.dll XSS technique stays unpatched by Microsoft (no CVE, not KEV), so the capability remains exploitable and warrants monitoring.
Sources cited for ChainedShark APT (Actor240820)
- NSFOCUS Fuying Lab — ChainedShark (Actor240820) APT Analysis
- GrimResource — Microsoft Management Console for Initial Access and Evasion (Elastic Security Labs)
- DotNetToJScript — .NET Code Execution via Script Engines
- DirtyCLR — Stealthy .NET Execution Technique
- GrimResource Indicators — Elastic Labs GitHub
- Elastic Security Labs — GrimResource YARA Rule (Windows_GrimResource_MMC)
- APDS.dll XSS Research — From HTTP Domain to res:// Domain
Detection coverage for TL-2026-0082
As of 2026-02-13, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0082 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.