Threat reportAPTTL-2026-0082

ChainedShark APT (Actor240820): State-Sponsored Espionage Targeting Chinese Research Institutions via GrimResource & LinkedShell

mediumMONITORING

ChainedShark APT (Actor240820) (TL-2026-0082) is a medium-severity advanced persistent threat campaign, first published 2026-02-13. It is attributed to ChainedShark with medium confidence, maps to 30 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 12 detection rules and 31 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
30MITRE ATT&CK
Actors
1ChainedShark
Detection rules
12SPL · KQL · Sigma
IOCs
31Indicators of compromise

Key facts for TL-2026-0082

Threat ID
TL-2026-0082
Severity
MEDIUM
Status
MONITORING
Category
APT
First published
Last reviewed
Attribution
ChainedShark
Attribution confidence
MEDIUM
Motivation
ESPIONAGE
Target sectors
Education, Research, Government, Academia, Marine Technology, International Relations, Defense Research, Think Tanks
Target regions
China
Detection rules
12
Indicators of compromise
31

Malware and tooling in ChainedShark APT (Actor240820)

Malware and tooling: LinkedShell custom trojan — ChainedShark exclusive, high customization, advanced anti-forensic capabilities, LinkedShell custom trojan — high customization, advanced anti-forensic capabilities, first observed May 2024 in ChainedShark operations, LinkedShell — custom trojan with anti-forensic capabilities and high per-target customization (ChainedShark exclusive)

How ChainedShark APT (Actor240820) works

ChainedShark (Actor240820) is a state-sponsored APT group conducting espionage campaigns against Chinese university and research professionals specializing in international relations and marine technology, using GrimResource N-day exploitation and the custom LinkedShell trojan.

NSFOCUS Fuying Lab identified a state-sponsored threat actor designated Actor240820, codenamed ChainedShark, conducting persistent espionage campaigns against Chinese academic and research institutions since at least May 2024. The campaigns specifically target professionals in international relations and marine technology — two fields with direct geopolitical intelligence value for foreign state actors seeking insight into China's diplomatic positions and maritime capabilities. ChainedShark demonstrates state-level sophistication through multiple indicators: (1) Fluent Chinese-language social engineering using conference invitations and call-for-papers lures that convincingly mimic legitimate academic communications, (2) exploitation of the GrimResource N-day technique (disclosed by Elastic Security Labs in June 2024) to achieve code execution via specially crafted MSC (Microsoft Management Console) files, (3) deployment of LinkedShell, a custom trojan with advanced anti-forensic capabilities and high customization that has not been observed in any other threat actor's toolkit, (4) persistent targeting of the same individuals across multiple campaigns (May to November 2024), indicating dedicated intelligence collection requirements rather than opportunistic compromise. GrimResource exploits an old XSS vulnerability in apds.dll to execute JavaScript within the context of mmc.exe when a victim opens a crafted .msc file. The technique was initially disclosed by Elastic Security Labs and leverages DotNetToJScript for arbitrary code execution with minimal security warnings. ChainedShark's adoption of GrimResource within months of its public disclosure demonstrates rapid N-day weaponization capability — a hallmark of state-sponsored groups with dedicated vulnerability research teams. The LinkedShell trojan is purpose-built for long-term espionage: anti-forensic features hinder incident response, high customization allows per-target configuration, and the malware maintains persistent access for intelligence collection. The combination of academic targeting, Chinese-language fluency, marine technology focus, and diplomatic intelligence requirements suggests a state actor with specific geopolitical objectives related to the South China Sea, Taiwan Strait, or broader Indo-Pacific maritime disputes.

MITRE ATT&CK techniques used in TL-2026-0082

collection

T1005 Data from Local System; T1056 Input Capture; T1074 Data Staged; T1113 Screen Capture; T1114 Email Collection

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1202 Indirect Command Execution; T1218 System Binary Proxy Execution

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution; T1559 Inter-Process Communication; T1569 System Services

command-and-control

T1071 Application Layer Protocol; T1573 Encrypted Channel

discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

persistence

T1547 Boot or Logon Autostart Execution

initial-access

T1566 Phishing

resource-development

T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

reconnaissance

T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains

defense-impairment

T1685 Disable or Modify Tools

Remediation for ChainedShark APT (Actor240820)

Immediate actions

  • Block inbound MSC files in email gateways and web filters
  • Deploy ASR (Attack Surface Reduction) rules to restrict mmc.exe child process creation
  • Monitor for mmc.exe spawning unexpected child processes (cmd.exe, powershell.exe, dllhost.exe)
  • Alert on mmc.exe accessing apds.dll (file open event — not a library load)
  • Brief targeted personnel (international relations, marine technology researchers) on conference invite phishing

Workarounds

  • Rename or remove apds.dll if not required (breaks the GrimResource XSS chain)
  • Use Group Policy to restrict MSC file execution from user-writable directories
  • Deploy YARA rule from Elastic Security Labs for GrimResource MSC file detection

Longer-term hardening

  • Implement application whitelisting to restrict mmc.exe execution to IT-approved contexts
  • Deploy behavioral detection for DotNetToJScript execution patterns
  • Monitor for creation of redirect[*] files in INetCache directory from mmc.exe
  • Establish academic institution threat intelligence sharing for APT targeting awareness
  • Restrict MSC file association to prevent user-initiated execution from email attachments

Weaknesses (CWE) in ChainedShark APT (Actor240820)

CWE-79, CWE-94, CWE-829, CWE-502

Timeline of ChainedShark APT (Actor240820)

  • ChainedShark (Actor240820) conducts first observed campaign targeting Chinese university researchers in international relations with conference invitation lures. Custom LinkedShell trojan deployed. Source: NSFOCUS Fuying Lab
  • First GrimResource sample uploaded to VirusTotal (SHA-256: 14bcb7196143fd2b800385e9b32cfacd837007b0face71a73b546b53310258bb). Initially attributed to DPRK actors by Genians. Source: https://www.elastic.co/security-labs/grimresource
  • Elastic Security Labs publicly discloses GrimResource technique: XSS in apds.dll enables code execution via crafted MSC files in mmc.exe context. Provides detection rules and YARA signatures. Source: https://www.elastic.co/security-labs/grimresource
  • ChainedShark adopts GrimResource N-day technique within weeks of public disclosure, incorporating it into attack chain targeting Chinese researchers. Demonstrates rapid weaponization capability. Source: NSFOCUS Fuying Lab
  • NSFOCUS Fuying Lab designates the threat actor as Actor240820 based on first confirmed attribution date. Begins tracking persistent campaigns against Chinese academic institutions. Source: NSFOCUS Fuying Lab
  • ChainedShark campaigns continue through November 2024, targeting the SAME individuals from May campaign. Persistent re-targeting over 6+ months indicates dedicated intelligence collection requirements and specific victim interest. Source: NSFOCUS Fuying Lab
  • ChainedShark expands targeting to include Chinese marine technology researchers in addition to international relations academics. Marine technology targeting suggests intelligence requirements related to South China Sea, Taiwan Strait, or Indo-Pacific maritime capabilities. Source: NSFOCUS Fuying Lab
  • ThreadLinqs Intelligence begins tracking as TL-2026-0082 after RSS detection. State-sponsored espionage targeting Chinese academic institutions via GrimResource + LinkedShell. Source: ThreadLinqs Intelligence
  • NSFOCUS Fuying Lab publishes comprehensive analysis of ChainedShark (Actor240820) APT campaigns, LinkedShell trojan capabilities, and GrimResource exploitation chain. Source: NSFOCUS Fuying Lab
  • As of 2026-05-29, ChainedShark (Actor240820) shows no campaign activity since Nov 2024; NSFOCUS's Feb 2026 retrospective is purely historical, with no takedown, attribution, rebrand, or successor reported. The actor is effectively dormant, yet its GrimResource apds.dll XSS technique stays unpatched by Microsoft (no CVE, not KEV), so the capability remains exploitable and warrants monitoring.

Sources cited for ChainedShark APT (Actor240820)

Detection coverage for TL-2026-0082

As of 2026-02-13, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0082 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

12 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
31 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats