Behind the Trap: Mapping APT TH3BUG’s AKA Violin Panda Watering Hole Campaign with Poison Ivy
Advanced Persistent Threat (APT) actors continue to evolve but so do our methods to uncover and counter them.

Behind the Trap: Mapping APT TH3BUG’s Watering Hole Campaign with Poison Ivy
Advanced Persistent Threat (APT) actors continue to evolve but so do our methods to uncover and counter them. Recently, our threat intelligence team uncovered a watering hole attack campaign linked to the TH3BUG APT group, known for its strategic use of the Poison Ivy Remote Access Trojan (RAT).
In this post, we dive into how attackers silently compromise trusted websites, lure high-value targets, and deploy remote access malware all while hiding behind sophisticated infrastructure. By reconstructing the campaign’s service architecture, we expose their hidden ecosystem and provide actionable Indicators of Compromise (IOCs) to defend your organization.
What Is a Watering Hole Attack?
A watering hole attack is a targeted strategy where attackers compromise a website frequently visited by a specific group (e.g., an industry, government body, or geographic region). Instead of attacking targets directly, the attackers infect the “watering hole” then wait.
TH3BUG has refined this technique, compromising legitimate websites and injecting malicious scripts that redirect users to exploit kits. Once a system is compromised, Poison Ivy RAT is deployed for persistent access, surveillance, and lateral movement.
Who Is APT TH3BUG?
APT TH3BUG AKA Violin Panda is an elusive threat group known for cyber-espionage operations. Active since at least 2020, this group targets:
Government agencies:
1.Defense contractors
2.Energy sector entities
3.High-profile researchers and NGOs
Notable capabilities:
Highly targeted delivery via supply chain and watering hole attacks
Custom variants of off-the-shelf malware (e.g., Poison Ivy)
Infrastructure that rotates fast, using bulletproof hosting and domain shadowing
Infrastructure Mapping: Seeing the Threat Behind the Code

Our team traced the entire infection chain from compromised websites to payload delivery and mapped the infrastructure used in the campaign. Here’s what we uncovered:
Initial vector: Compromised sites injected with JavaScript that redirects to staging domains.
Staging domains: Temporarily active for less than 48 hours, hosting exploit kits.
Payload delivery: Poison Ivy RAT hosted on subdomains of legitimate-looking services.
C2 communications: Encrypted traffic to dynamic DNS domains using non-standard ports.
Mapping this infrastructure allowed us to identify patterns, track attacker behavior, and preemptively block future connections.
Indicators of Compromise (IOCs)
| Type | Value | Details / Notes |
|---|---|---|
| Domain (C2 / Control) | diff.qohub.info | Used as C2 domain in several samples. (Unit 42) |
| Domain (C2) | app.qohub.info | Another Poison Ivy control domain. (Unit 42) |
| Domain (Download Host) | uyghurweb.net | A legitimate site which was compromised to host malicious files. (Unit 42) |
| Download URLs | www.npec.com.tw/flash/diff.exe | Malware delivery via compromised or staging hosts. (Unit 42) |
| Download URLs | www.aanon.com.tw/flash/diff.exe | Part of the same delivery chain. (Unit 42) |
| Download URLs | uyghurweb.net/player/gmuweb.exe | Payload download & execution from the compromised site. (Unit 42) |
| Download URLs | uyghurweb.net/player/PYvBte.jar | This “.jar” file was actually a Windows executable / RAT. (Unit 42) |
| File Hash (MD5) | 18ad696f3459bf47f97734f2f14506e3 | “diff.exe” sample, first seen 2014‑07‑14. (Unit 42) |
| File Hash (MD5) | 1ea41812a0114e5c6ae76330e7b4af69 | Variant of “diff.exe”, same C2 domain. (Unit 42) |
| File Hash (MD5) | 7b0cb4d14d3d8b6ccc7453f7ddb33997 | MD5 of “PYvBte.jar” executable masquerading under .jar. (Unit 42) |
| File Hash (MD5) | efad656db0f9cc92b1e15dc9c540e407 | Sample “setup.exe”, another Poison Ivy variant. (Unit 42) |
| File Hash (MD5) | 0cabd6aec2555e64bdf39320f338e027 | “AppletLow.jar”, downloaded from a compromised location. (Unit 42) |
How to Protect Against TH3BUG
To defend against this type of campaign:
1.Block listed IPs, domains, and hashes at your perimeter 2.Inspect outbound connections to non-standard ports
3.Implement SSL inspection to catch encrypted C2 traffic
4.Enable PowerShell & script logging for early detection
5.Harden web browser security on high-risk endpoints
6.Use network mapping to understand exposure and asset communication paths
See What Attackers Are Building Behind the Scenes
Watering hole attacks are deceptive targeting not your defenses, but your trust. The only way to fight back is by making their infrastructure visible.
At Alpha Cyber, we specialize in identifying and mapping attacker ecosystems before they reach your users. From early threat detection to infrastructure takedown intelligence, our solutions help you take proactive control.
Need a threat infrastructure assessment? Contact us today.



