{"id":35070,"date":"2026-02-13T08:11:25","date_gmt":"2026-02-13T08:11:25","guid":{"rendered":"https:\/\/nsfocusglobal.com\/?p=33192"},"modified":"2026-04-13T08:52:21","modified_gmt":"2026-04-13T08:52:21","slug":"top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group","status":"publish","type":"post","link":"https:\/\/nsfocusglobal.com\/pt-br\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/","title":{"rendered":"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group"},"content":{"rendered":"\n<p>In 2025, NSFOCUS&nbsp;Fuying Lab disclosed a new APT group targeting China\u2019s scientific research sector, dubbed &#8220;ChainedShark&#8221; (tracking number: Actor240820). Been active since May 2024, the group\u2019s operations are marked by high strategic coherence and technical sophistication. Its primary targets are professionals in Chinese universities and research institutions specializing in international relations, marine technology, and related fields, with the intent to steal sensitive data and intelligence in diplomacy and marine technology.<\/p>\n\n\n\n<p>ChainedShark exhibits clear geopolitical motivations, focusing its attacks on experts and scholars in international relations and marine sciences within Chinese academic and research institutions. The group demonstrates strong social engineering capabilities, crafting fluent, natural, and high-quality Chinese-language lures. It skillfully exploits professional scenarios\u2014such as conference invitations and academic call-for-papers\u2014to create deceptive attack vectors, effectively lowering targets\u2019 guard.<\/p>\n\n\n\n<p>Technically, ChainedShark operates at the level of a state-sponsored attack team. Its arsenal integrates N-day vulnerability exploits and highly complex custom trojans, featuring meticulously designed attack chains and payloads with strong evasion and stealth capabilities. This indicates a mature attack infrastructure and continuous weapon development capacity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Event Summary<\/h2>\n\n\n\n<p>ChainedShark\u2019s attack campaigns, while maintaining consistent strategic objectives, have demonstrated a clear evolutionary trajectory in both tactics and technical execution.<\/p>\n\n\n\n<p>First Wave (May 2024): This initial attack remains the most complex operation identified to date. The attack chain deployed a custom-developed trojan, LinkedShell, characterized by high customization and advanced anti-forensic capabilities. The technical intricacies of this trojan underscore the group\u2019s robust initial weaponization capabilities.<\/p>\n\n\n\n<p>Subsequent Attacks (August\u2013November 2024): In later operations, the attackers adjusted their tactics. By successfully exploiting the GrimResource vulnerability (publicly disclosed in June 2024), they significantly streamlined the attack process, reflecting a strategic shift toward leveraging public vulnerabilities to enhance efficiency and cost-effectiveness.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Event Analysis<\/h2>\n\n\n\n<p>Multidimensional clue correlation linked separate attack events across different timeframes, painting a comprehensive profile of the threat actor.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Target Consistency: The same individuals were targeted in both the May and November 2024 attacks, strongly indicating the directed and persistent nature of these operations.<\/li>\n\n\n\n<li>Lure Homogeneity: Despite variations in payloads, the phishing emails used in different attacks shared striking similarities in subject selection, phrasing, and social engineering tactics\u2014forming a behavioral \u201cfingerprint.\u201d<\/li>\n<\/ul>\n\n\n\n<p>This correlational analysis not only provides critical evidence for attribution but also reveals that ChainedShark adheres to a mature social engineering script and attack management process throughout its prolonged campaigns.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In 2025, NSFOCUS&nbsp;Fuying Lab disclosed a new APT group targeting China\u2019s scientific research sector, dubbed &#8220;ChainedShark&#8221; (tracking number: Actor240820). Been active since May 2024, the group\u2019s operations are marked by high strategic coherence and technical sophistication. Its primary targets are professionals in Chinese universities and research institutions specializing in international relations, marine technology, and related [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":33239,"comment_status":"open","ping_status":"open","sticky":false,"template":"post-templates\/single-layout-8.php","format":"standard","meta":{"_acf_changed":false,"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[3],"tags":[93,357,741],"class_list":["post-35070","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-apt","tag-cybersecurity-insights","tag-web-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group - NSFOCUS<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group - NSFOCUS\" \/>\n<meta property=\"og:description\" content=\"In 2025, NSFOCUS&nbsp;Fuying Lab disclosed a new APT group targeting China\u2019s scientific research sector, dubbed &quot;ChainedShark&quot; (tracking number:\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/\" \/>\n<meta property=\"og:site_name\" content=\"NSFOCUS\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-13T08:11:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-13T08:52:21+00:00\" \/>\n<meta name=\"author\" content=\"NSFOCUS\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group - NSFOCUS\" \/>\n<meta name=\"twitter:description\" content=\"In 2025, NSFOCUS&nbsp;Fuying Lab disclosed a new APT group targeting China\u2019s scientific research sector, dubbed &quot;ChainedShark&quot; (tracking number:\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"NSFOCUS\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/\"},\"author\":{\"name\":\"NSFOCUS\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\"},\"headline\":\"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group\",\"datePublished\":\"2026-02-13T08:11:25+00:00\",\"dateModified\":\"2026-04-13T08:52:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/\"},\"wordCount\":398,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"keywords\":[\"APT\",\"Cybersecurity Insights\",\"Web Security\"],\"articleSection\":[\"Blog\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/\",\"name\":\"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group - NSFOCUS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2026-02-13T08:11:25+00:00\",\"dateModified\":\"2026-04-13T08:52:21+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nsfocusglobal.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#website\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/\",\"name\":\"NSFOCUS\",\"description\":\"Security Made Smart and Simple\",\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nsfocusglobal.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\",\"name\":\"NSFOCUS\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"width\":248,\"height\":36,\"caption\":\"NSFOCUS\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\",\"name\":\"NSFOCUS\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"caption\":\"NSFOCUS\"},\"sameAs\":[\"https:\\\/\\\/nsfocusglobal.com\"],\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group - NSFOCUS","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/","og_locale":"pt_BR","og_type":"article","og_title":"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group - NSFOCUS","og_description":"In 2025, NSFOCUS&nbsp;Fuying Lab disclosed a new APT group targeting China\u2019s scientific research sector, dubbed \"ChainedShark\" (tracking number:","og_url":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/","og_site_name":"NSFOCUS","article_published_time":"2026-02-13T08:11:25+00:00","article_modified_time":"2026-04-13T08:52:21+00:00","author":"NSFOCUS","twitter_card":"summary_large_image","twitter_title":"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group - NSFOCUS","twitter_description":"In 2025, NSFOCUS&nbsp;Fuying Lab disclosed a new APT group targeting China\u2019s scientific research sector, dubbed \"ChainedShark\" (tracking number:","twitter_misc":{"Escrito por":"NSFOCUS","Est. tempo de leitura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/#article","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/"},"author":{"name":"NSFOCUS","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d"},"headline":"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group","datePublished":"2026-02-13T08:11:25+00:00","dateModified":"2026-04-13T08:52:21+00:00","mainEntityOfPage":{"@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/"},"wordCount":398,"commentCount":0,"publisher":{"@id":"https:\/\/nsfocusglobal.com\/#organization"},"image":{"@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/#primaryimage"},"thumbnailUrl":"","keywords":["APT","Cybersecurity Insights","Web Security"],"articleSection":["Blog"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/","url":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/","name":"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group - NSFOCUS","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/#primaryimage"},"image":{"@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/#primaryimage"},"thumbnailUrl":"","datePublished":"2026-02-13T08:11:25+00:00","dateModified":"2026-04-13T08:52:21+00:00","breadcrumb":{"@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/nsfocusglobal.com\/top-security-incidents-of-2025-the-emergence-of-the-chainedshark-apt-group\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nsfocusglobal.com\/"},{"@type":"ListItem","position":2,"name":"Top Security Incidents of 2025: \u00a0The Emergence of the ChainedShark APT Group"}]},{"@type":"WebSite","@id":"https:\/\/nsfocusglobal.com\/#website","url":"https:\/\/nsfocusglobal.com\/","name":"NSFOCUS","description":"Security Made Smart and Simple","publisher":{"@id":"https:\/\/nsfocusglobal.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nsfocusglobal.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/nsfocusglobal.com\/#organization","name":"NSFOCUS","url":"https:\/\/nsfocusglobal.com\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/logo\/image\/","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","width":248,"height":36,"caption":"NSFOCUS"},"image":{"@id":"https:\/\/nsfocusglobal.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d","name":"NSFOCUS","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","caption":"NSFOCUS"},"sameAs":["https:\/\/nsfocusglobal.com"],"url":"https:\/\/nsfocusglobal.com\/pt-br\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/35070","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/comments?post=35070"}],"version-history":[{"count":1,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/35070\/revisions"}],"predecessor-version":[{"id":35598,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/35070\/revisions\/35598"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media?parent=35070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/categories?post=35070"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/tags?post=35070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}