# ChainedShark APT (Actor240820): State-Sponsored Espionage Targeting Chinese Research Institutions via GrimResource & LinkedShell

> ChainedShark (Actor240820) is a state-sponsored APT group conducting espionage campaigns against Chinese university and research professionals specializing in international relations and marine technology, using GrimResource N-day exploitation and the custom LinkedShell trojan.

- **Published:** 2026-02-13T09:46:41Z
- **Last reviewed:** 2026-02-13T09:46:41Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0082
- **ID:** TL-2026-0082
- **Severity:** MEDIUM
- **Category:** APT
- **Status:** MONITORING
- **Actor:** ChainedShark
- **Detections:** 12 · **IOCs:** 31 (full data via the Threadlinqs MCP server — Purple tier)

## Description

NSFOCUS Fuying Lab identified a state-sponsored threat actor designated Actor240820, codenamed ChainedShark, conducting persistent espionage campaigns against Chinese academic and research institutions since at least May 2024. The campaigns specifically target professionals in international relations and marine technology — two fields with direct geopolitical intelligence value for foreign state actors seeking insight into China's diplomatic positions and maritime capabilities. ChainedShark demonstrates state-level sophistication through multiple indicators: (1) Fluent Chinese-language social engineering using conference invitations and call-for-papers lures that convincingly mimic legitimate academic communications, (2) exploitation of the GrimResource N-day technique (disclosed by Elastic Security Labs in June 2024) to achieve code execution via specially crafted MSC (Microsoft Management Console) files, (3) deployment of LinkedShell, a custom trojan with advanced anti-forensic capabilities and high customization that has not been observed in any other threat actor's toolkit, (4) persistent targeting of the same individuals across multiple campaigns (May to November 2024), indicating dedicated intelligence collection requirements rather than opportunistic compromise. GrimResource exploits an old XSS vulnerability in apds.dll to execute JavaScript within the context of mmc.exe when a victim opens a crafted .msc file. The technique was initially disclosed by Elastic Security Labs and leverages DotNetToJScript for arbitrary code execution with minimal security warnings. ChainedShark's adoption of GrimResource within months of its public disclosure demonstrates rapid N-day weaponization capability — a hallmark of state-sponsored groups with dedicated vulnerability research teams. The LinkedShell trojan is purpose-built for long-term espionage: anti-forensic features hinder incident response, high customization allows per-target configuration, and the malware maintains persistent access for intelligence collection. The combination of academic targeting, Chinese-language fluency, marine technology focus, and diplomatic intelligence requirements suggests a state actor with specific geopolitical objectives related to the South China Sea, Taiwan Strait, or broader Indo-Pacific maritime disputes.

## MITRE ATT&CK

- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1569 System Services
- T1559 Inter-Process Communication
- T1218 System Binary Proxy Execution
- T1055 Process Injection
- T1036 Masquerading
- T1685 Disable or Modify Tools
- T1070 Indicator Removal
- T1027 Obfuscated Files or Information
- T1202 Indirect Command Execution
- T1547 Boot or Logon Autostart Execution
- T1082 System Information Discovery
- T1087 Account Discovery
- T1005 Data from Local System
- T1074 Data Staged
- T1041 Exfiltration Over C2 Channel
- T1071 Application Layer Protocol
- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1589 Gather Victim Identity Information
- T1593 Search Open Websites/Domains
- T1203 Exploitation for Client Execution
- T1056 Input Capture
- T1083 File and Directory Discovery
- T1573 Encrypted Channel
- T1585 Establish Accounts
- T1113 Screen Capture
- T1114 Email Collection

## Sources

- [NSFOCUS Fuying Lab — ChainedShark (Actor240820) APT Analysis](https://blog.nsfocus.net/chainedshark-actor240820/)
- [GrimResource — Microsoft Management Console for Initial Access and Evasion (Elastic Security Labs)](https://www.elastic.co/security-labs/grimresource)
- [DotNetToJScript — .NET Code Execution via Script Engines](https://github.com/tyranid/DotNetToJScript)
- [DirtyCLR — Stealthy .NET Execution Technique](https://github.com/ipSlav/DirtyCLR)
- [GrimResource Indicators — Elastic Labs GitHub](https://github.com/elastic/labs-releases/tree/main/indicators/grimresource)
- [APDS.dll XSS Research — From HTTP Domain to res:// Domain](https://medium.com/@knownsec404team/from-http-domain-to-res-domain-xss-by-using-ie-adobes-pdf-activex-plugin-ba4f082c8199)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0082
