APT / THREAT GROUP🕵️ ESPIONAGEADVANCED

SLIME88

🇨🇳China-attributed
1
aliases
Last seen:Jun 13, 2026

Intelligence Profile

SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices and establishing an ORB network tracked as GOBLIN14. The group has targeted IT and manufacturing entities in the US, South Korea, India, and France. Additionally, SLIME88 has aimed at Taiwan’s energy sector using phishing emails and fake certificate installers to deploy backdoor programs like AdaptixC2 and CobaltStrike. They often utilize Cloudflare to obscure their C2 IP addresses, evading detection.

Threat Analysis

SLIME88 is a advanced-sophistication threat actor attributed to China, engaged in cyber operations with a primary motivation of espionage.

The group's espionage-oriented operations suggest a state-sponsored or state-aligned mandate, typically focused on stealing intellectual property, government secrets, or military intelligence. Targets are usually selected for strategic value rather than financial gain.

Classified as an advanced threat actor, SLIME88 likely develops or acquires zero-day exploits, employs custom malware toolchains, and demonstrates long-term persistence capabilities — hallmarks of a well-resourced operation consistent with nation-state backing.

External References

Quick Facts

TypeAPT / Threat Group
Motivation🕵️ espionage
Sophisticationadvanced
Origin🇨🇳 China
Aliases1
SourceMalpedia

Also Known As

SLIME88

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.