Menu
Browse

Cyber Threat Actor: APT20

Aliases 3 aliases
Actor Type Location Known Incidents
 Icon
Nation State
China
1 incident
Characteristics
Threat actor characteristics available to members
Profile

The threat actor known as Evil Shadow Team, also tracked as TA428 and APT20, is identified as a Chinese hacking group. The group is based in China, and public reporting explicitly links the alias Evil Shadow Team to a Chinese hacker collective, noting its involvement in defacing the Indian Microsoft Store a few years prior to the 2013 Malaysian incident. The aliases are used interchangeably in open‑source reporting to refer to the same activity set.

The actor’s observed activity focuses on defacing websites of government entities and private sector organizations. Targets have included national ministries, government portals, and commercial sites across multiple sectors. The defacements are accompanied by politically charged messages, such as a “Happy New Year” greeting paired with anti‑government statements. These actions appear intended to convey a political message and disrupt the normal operation of the targeted online services.

The group’s primary tactic involves gaining unauthorized access to web servers and replacing the existing content with its own messages. In the Malaysian incident, the attackers took both the Ministry of Education site and the Malaysia My Second Home Programme portal offline after the defacement. Over two dozen additional commercial websites were simultaneously altered with similar politically motivated content during the same campaign. No specific malware families or intrusion tools are described in the available reporting for this actor’s operations.

A representative example is the December 31, 2013 defacement of the Malaysian Ministry of Education website and an accompanying government portal, which coincided with the alteration of dozens of commercial sites. Earlier reporting notes that the same Evil Shadow Team was responsible for defacing the Indian Microsoft Store a couple of years before the Malaysian attack. Both incidents involved the replacement of legitimate content with political statements and resulted in the temporary unavailability of the affected services. These cases illustrate the group’s reliance on website defacement as a means of delivering its message and causing disruption.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
23 sources