APTTrail: Heyoka indicators and references

Fecha
18 Jun 2026
Actor
heyoka
Tipo
Ioc
Pais
United States
Sector
-
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

30IOCs
0TTPs
heyokaActor
United StatesPais
Executive Summary
APTTrail mantiene indicadores publicos asociados a Heyoka. Aliases observados: Heyoka, Mongall, UNC94. Conteo por tipo: domain: 107, ipv4: 4, url: 3.

Key Points

  • https://twitter.com/AndreGironda/status/1757929271962550534
  • https://twitter.com/alex_lanstein/status/1757855436261245194
  • https://www.sentinelone.com/labs/aoqin-dragon-newly-discovered-chinese-linked-apt-has-been-quietly-spying-on-organizations-for-10-years/
  • https://www.virustotal.com/gui/file/2110627fc40daaa7903210e310ee0f9ee8b79f47b6188431eb67b5f94e03a139/detection
  • https://www.virustotal.com/gui/file/313355f5ecf62401247c61e147b43f74eb7fcbfdf4856c7270079265cac07026/detection

Resumen APTTrail

APTTrail mantiene indicadores publicos asociados a Heyoka. Aliases observados: Heyoka, Mongall, UNC94. Conteo por tipo: domain: 107, ipv4: 4, url: 3.

Indicadores de Compromiso (IOCs)

TipoValorContexto
Domainadsoft.nameAPTTrail
Domainback.satunusa.orgAPTTrail
Domainbaomoi.vnptnet.infoAPTTrail
Domainbbw.fushing.orgAPTTrail
Domainbca.zdungk.comAPTTrail
Domainbkav.manlish.netAPTTrail
Domainbkav.welikejack.comAPTTrail
Domainbkavonline.vnptnet.infoAPTTrail
Domainbluesky1234.comAPTTrail
Domainbush2015.netAPTTrail
Domaincl.weststations.comAPTTrail
Domaincloundvietnam.comAPTTrail
Domaincomnnet.netAPTTrail
Domaincpt.vnptnet.infAPTTrail
Domaincvb.hotcup.pwAPTTrail
Domaindellyou.comAPTTrail
Domaindinhk.netAPTTrail
Domaindns.foodforthought1.comAPTTrail
Domaindns.lioncity.topAPTTrail
Domaindns.satunusa.orgAPTTrail
Domaindns.zdungk.comAPTTrail
Domainds.vdcvn.comAPTTrail
Domainds.xrayccc.topAPTTrail
Domaindungk.comAPTTrail
Domainfacebookmap.topAPTTrail
Domainfbcl2.adsoft.nameAPTTrail
Domainfbcl2.softad.netAPTTrail
Domainflower2.yyppmm.comAPTTrail
Domainfollowag.orgAPTTrail
Domainfoodforthought1.comAPTTrail

Referencias

Diamond Model

Adversary
heyoka
Ver perfil →
Victim
APTTrail: Heyoka indicators and references
United States
Capability
Ioc
Infrastructure
adsoft.name
back.satunusa.org
baomoi.vnptnet.info
bbw.fushing.org

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain adsoft.name APTTrail VT OffSec SOCRadar
Domain back.satunusa.org APTTrail VT OffSec SOCRadar
Domain baomoi.vnptnet.info APTTrail VT OffSec SOCRadar
Domain bbw.fushing.org APTTrail VT OffSec SOCRadar
Domain bca.zdungk.com APTTrail VT OffSec SOCRadar
Domain bkav.manlish.net APTTrail VT OffSec SOCRadar
Domain bkav.welikejack.com APTTrail VT OffSec SOCRadar
Domain bkavonline.vnptnet.info APTTrail VT OffSec SOCRadar
Domain bluesky1234.com APTTrail VT OffSec SOCRadar
Domain bush2015.net APTTrail VT OffSec SOCRadar
Domain cl.weststations.com APTTrail VT OffSec SOCRadar
Domain cloundvietnam.com APTTrail VT OffSec SOCRadar
Domain comnnet.net APTTrail VT OffSec SOCRadar
Domain cpt.vnptnet.inf APTTrail VT OffSec SOCRadar
Domain cvb.hotcup.pw APTTrail VT OffSec SOCRadar
Domain dellyou.com APTTrail VT OffSec SOCRadar
Domain dinhk.net APTTrail VT OffSec SOCRadar
Domain dns.foodforthought1.com APTTrail VT OffSec SOCRadar
Domain dns.lioncity.top APTTrail VT OffSec SOCRadar
Domain dns.satunusa.org APTTrail VT OffSec SOCRadar
Domain dns.zdungk.com APTTrail VT OffSec SOCRadar
Domain ds.vdcvn.com APTTrail VT OffSec SOCRadar
Domain ds.xrayccc.top APTTrail VT OffSec SOCRadar
Domain dungk.com APTTrail VT OffSec SOCRadar
Domain facebookmap.top APTTrail VT OffSec SOCRadar
Domain fbcl2.adsoft.name APTTrail VT OffSec SOCRadar
Domain fbcl2.softad.net APTTrail VT OffSec SOCRadar
Domain flower2.yyppmm.com APTTrail VT OffSec SOCRadar
Domain followag.org APTTrail VT OffSec SOCRadar
Domain foodforthought1.com APTTrail VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor heyoka en el blog → Ver heyoka en IntelTracker → URL IntelTracker: twitter.com→ URL IntelTracker: twitter.com→ URL IntelTracker: www.sentinelone.com→ URL IntelTracker: www.virustotal.com→ URL IntelTracker: www.virustotal.com→ URL IntelTracker: www.virustotal.com → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com→ Fuente OSINT: twitter.com→ Fuente OSINT: twitter.com→ Fuente OSINT: www.sentinelone.com→ Fuente OSINT: www.virustotal.com → Buscar heyoka en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes