# Threat actor

Type: Company

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/threat-actor
Canonical HTML page: https://getcyberbrief.com/entity/threat-actor

## Timeline

- **2026-09-30**: Bitget discloses breach — Bitget reveals the zero-day breach and shares findings from SlowMist and Mandiant.
- **2026-09-25**: Crypto theft executed — Theft transfers occurred between 02:31 and 05:23 UTC+8, spanning nearly three hours across multiple blockchains.
- **2026-09-24**: Privileged access to security appliances — Mandiant reports threat actor gained unauthorized privileged access to third-party security appliances A and B, deployed a web shell on appliance B, and established C2.
- **2026-09-23**: Additional hidden-script activity — Similar hidden-script activity was observed on two other nodes.
- **2026-08-31**: Earliest malicious activity — Logs show a service on one of Product A's nodes was affected by a zero-day vulnerability; attacker ran a hidden script and accessed a database password.

## Recent coverage (1 stories)

### Bitget Lost $387.5M After Zero-Day in Third-Party Security Appliances
2026-10-01 06:08:30 · Sentiment: Strongly negative · Impact: 8/10 · Sources: 2

A zero-day in two third-party security appliances gave attackers privileged access to Bitget's wallet environment. Mandiant and SlowMist traced lateral movement to the production wallet job server, where a custom withdrawal tool moved $387.5 million.
Full story: https://getcyberbrief.com/story/bitget-zero-day-security-appliances-387m

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.