216.73.216.6

Bookworm to Stately Taurus Using the Attribution Framework

· Published 25/09/2025 14:11 · Modified 25/09/2025 19:01

Export JSON

Essential information

Published
25/09/2025 14:11
Modified
25/09/2025 19:01
Tags
2025-09-25 apt attribution bookworm china infrastructure malware pubload southeast asia toneshell victimology
Related entities
1 intrusion sets (apt), 1 malware, 1 others

Description

This analysis examines the family and its connection to the Chinese group Stately Taurus. Using a structured framework, the study evaluates tactics, tooling, operational security, , and timelines to establish a high-confidence link between and Stately Taurus. Key evidence includes shared program database paths, overlapping command and control , and consistent targeting of Southeast Asian governments. The framework assigns scores to each piece of evidence, resulting in an overall confidence score of 58.4 out of 100, indicating strong confidence in the connection. This systematic approach aims to improve analytical rigor and collaboration in threat intelligence.

External references