Alpha Cyber

Behind the Trap: Mapping APT TH3BUG’s AKA Violin Panda Watering Hole Campaign with Poison Ivy

Advanced Persistent Threat (APT) actors continue to evolve but so do our methods to uncover and counter them.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Violin Panda APT

Behind the Trap: Mapping APT TH3BUG’s Watering Hole Campaign with Poison Ivy

Advanced Persistent Threat (APT) actors continue to evolve  but so do our methods to uncover and counter them. Recently, our threat intelligence team uncovered a watering hole attack campaign linked to the TH3BUG APT group, known for its strategic use of the Poison Ivy Remote Access Trojan (RAT).

In this post, we dive into how attackers silently compromise trusted websites, lure high-value targets, and deploy remote access malware all while hiding behind sophisticated infrastructure. By reconstructing the campaign’s service architecture, we expose their hidden ecosystem and provide actionable Indicators of Compromise (IOCs) to defend your organization.

What Is a Watering Hole Attack?

A watering hole attack is a targeted strategy where attackers compromise a website frequently visited by a specific group (e.g., an industry, government body, or geographic region). Instead of attacking targets directly, the attackers infect the “watering hole” then wait.

TH3BUG has refined this technique, compromising legitimate websites and injecting malicious scripts that redirect users to exploit kits. Once a system is compromised, Poison Ivy RAT is deployed for persistent access, surveillance, and lateral movement.

Who Is APT TH3BUG?

APT TH3BUG AKA Violin Panda is an elusive threat group known for cyber-espionage operations. Active since at least 2020, this group targets:

Government agencies:
   1.Defense contractors
   2.Energy sector entities
   3.High-profile researchers and NGOs

Notable capabilities:

Highly targeted delivery via supply chain and watering hole attacks
Custom variants of off-the-shelf malware (e.g., Poison Ivy)
Infrastructure that rotates fast, using bulletproof hosting and domain shadowing

Infrastructure Mapping: Seeing the Threat Behind the Code

APT-20 AKA theb3g Graph

Our team traced the entire infection chain from compromised websites to payload delivery and mapped the infrastructure used in the campaign. Here’s what we uncovered:

Initial vector: Compromised sites injected with JavaScript that redirects to staging domains.
Staging domains: Temporarily active for less than 48 hours, hosting exploit kits.
Payload delivery: Poison Ivy RAT hosted on subdomains of legitimate-looking services.
C2 communications: Encrypted traffic to dynamic DNS domains using non-standard ports.

Mapping this infrastructure allowed us to identify patterns, track attacker behavior, and preemptively block future connections.

Indicators of Compromise (IOCs)

TypeValueDetails / Notes
Domain (C2 / Control)diff.qohub.infoUsed as C2 domain in several samples. (Unit 42)
Domain (C2)app.qohub.infoAnother Poison Ivy control domain. (Unit 42)
Domain (Download Host)uyghurweb.netA legitimate site which was compromised to host malicious files. (Unit 42)
Download URLswww.npec.com.tw/flash/diff.exeMalware delivery via compromised or staging hosts. (Unit 42)
Download URLswww.aanon.com.tw/flash/diff.exePart of the same delivery chain. (Unit 42)
Download URLsuyghurweb.net/player/gmuweb.exePayload download & execution from the compromised site. (Unit 42)
Download URLsuyghurweb.net/player/PYvBte.jarThis “.jar” file was actually a Windows executable / RAT. (Unit 42)
File Hash (MD5)18ad696f3459bf47f97734f2f14506e3“diff.exe” sample, first seen 2014‑07‑14. (Unit 42)
File Hash (MD5)1ea41812a0114e5c6ae76330e7b4af69Variant of “diff.exe”, same C2 domain. (Unit 42)
File Hash (MD5)7b0cb4d14d3d8b6ccc7453f7ddb33997MD5 of “PYvBte.jar” executable masquerading under .jar. (Unit 42)
File Hash (MD5)efad656db0f9cc92b1e15dc9c540e407Sample “setup.exe”, another Poison Ivy variant. (Unit 42)
File Hash (MD5)0cabd6aec2555e64bdf39320f338e027“AppletLow.jar”, downloaded from a compromised location. (Unit 42)

How to Protect Against TH3BUG

To defend against this type of campaign:

 1.Block listed IPs, domains, and hashes at your perimeter   2.Inspect outbound connections to non-standard ports
 3.Implement SSL inspection to catch encrypted C2 traffic
 4.Enable PowerShell & script logging for early detection
 5.Harden web browser security on high-risk endpoints
 6.Use network mapping to understand exposure and asset communication paths

See What Attackers Are Building Behind the Scenes

Watering hole attacks are deceptive targeting not your defenses, but your trust. The only way to fight back is by making their infrastructure visible.

At Alpha Cyber, we specialize in identifying and mapping attacker ecosystems before they reach your users. From early threat detection to infrastructure takedown intelligence, our solutions help you take proactive control.

Need a threat infrastructure assessment? Contact us today.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]