GREFGREF

Also known as: GREF

Known aliases
1

Profile

GREF is a China-aligned APT group that has been active since at least March 2017. They are known for using custom backdoors, loaders, and ancillary tools in their targeted attacks. Recently, they have been attributed to two active Android campaigns that distribute the BadBazaar malware through malicious apps on official and alternative app stores. GREF has targeted Android users, particularly Uyghurs and other Turkic ethnic minorities outside of China, using trojanized versions of popular messaging apps like Signal and Telegram.

Aliases· 1

GREF

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
GreyEnergy
Software
JadeRAT
Group
APT17
Group
APT19
Group
APT41
Actor
Ferocious Kitten
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.