
Threat Intelligence Pioneer, Born in Asia
Where threat intelligence meets decisive action. TeamT5 provides the visibility organizations need to minimize exposure and master cyber preparedness.
APT Threat Landscape in APAC 2025: Industrialization of Intrusions
With geopolitical tensions continuing to escalate across the APAC region, APT activities in the region are intensifying in both volume and sophistication.
Read nowStay ahead of attackers with intelligence-driven cybersecurity from TeamT5
More
 nasa-Q1p7bh3SHj8-unsplash.jpg)
 ben-sweet-2LowviVHZ-E-unsplash_1.jpg)
Intelligence that powers proactive defense
TeamT5 turns threat intelligence into actionable security, helping organizations detect threats earlier, respond faster, and strengthen cyber resilience
Unmatched Asia-Pacific threat insights
Unique intelligence on Asia-Pacific threat actors and campaigns to help organizations defend against targeted attacks.
Deep expertise in advanced threats
In-depth research on cyber espionage and APTs, exposing attacker tactics to counter advanced threats.
Discover how TeamT5 transforms threat intelligence into powerful defense for your organization.


Proactively hunt for advanced threats
ThreatSonar proactively hunts hidden intruders using intelligence-driven endpoint forensics, enabling organizations to detect suspicious activity, uncover root causes, and stop threats early.
See how it works
Comprehensive endpoint risk assessment
Quickly discover assets, detect vulnerabilities, and prioritize remediation. With intelligence-driven risk assessment, it enables faster mitigation of critical exposures and strengthens overall cyber resilience.
See how it works
Defense-in-depth for advanced threat protection
Stop ransomware instantly. ThreatSonar Anti-Ransomware delivers precise detection and real-time response to block lateral movement and encryption.
See how it worksTurning threat intelligence into decisive action
Act faster. Stop threats before they impact the business.
Tracking advanced cyber threats and nation-state activities across APAC.
Analyze threats to identify emerging risks.
Continuously tracking attackers and their evolving tactics.
Industry recognition & global trust
Award-winning cybersecurity innovation recognized by global experts and international industry standards.

ThreatSonar Anti-Ransomware solution is awarded 2024 Computex Best Choice Award - Golden Award

ThreatSonar Anti-Ransomware and ThreatVision solution are awarded 2026 Taiwan Excellence Award

TeamT5 Named as Taiwanese Threat Intelligence Company of the Year by Frost & Sullivan
Security that delivers results
Learn how TeamT5 helps 500+ organizations identify critical threats and respond with greater speed and confidence


Extend threat hunting services to overseas bases
Macnica’s ‘Mpression Service’ powers expert threat hunting with TeamT5 ThreatSonar, combining forensic precision with intelligence for superior detection.


Enhances incident handling service with advanced threat hunting capabilities
Accelerate investigations with ThreatSonar. Featuring thousands of built-in APT signatures, our platform provides the deep endpoint visibility needed to uncover hidden threats instantly.
Discover the latest threat trends in Asia Pacific
Access expert perspectives, threat intelligence updates, and in-depth research to better understand today’s cyber threat landscape.

Chinese Darcula Phishing Kit Harvesting Taiwanese Credit Card Data
Campaign Snapshot Campaign Timeframe: Jan 2026 to May 2026 Delivery Methods: Phishing Victim Country: Taiwan Phishing Kit: Darcula Actor Assessment: Chinese-speaking Executive Summary In May, we intercepted a phishing campaign harvesting Taiwanese credit card data. The threat actor leveraged a fake Taiwanese e-invoice platform to lure victims into submitting their credit card information through phishing pages. Our technical analysis found that the campaign encrypts victim data using the Rabbit encryption algorithm. The Rabbit encryption algorithm is the same encryption mechanism previously observed in the Darcula phishing kit. Based on this technical overlap, we assess with high confidence that the campaign was conducted using the Darcula phishing kit. We list all the malicious URLs in the IoCs section below. 1. Phishing Emails In this campaign, the actor delivered the phishing emails from a compromised email account belonging to Korea University[1]. In these emails, the actor impersonated the Taiwanese e-commerce platform MOMO and instructed victims to click the malicious links to verify their e-invoice. The actor prepared several malicious URLs that direct victims to the fake e-invoice platform: - https://0023.ehrscripts.com/ - https://av11.pdjekqa.online/ - https://einvoiceg.com/gov/ - https://einvoicegs.com/gov/ 2. Fake Taiwanese E-invoice Platform At the time of our analysis, we were only able to access two URLs https://einvoiceg.com/gov/ and https://einvoicegs.com/gov/ . The two URLs show the page identical to the legitimate e-invoice platform. However, the icon of the page displays the logo of Taiwanese commercial bank CTBC rather than the logo of Ministry of Finance used by the legitimate site. Figure 1: The fake e-invoice platform While the fake e-invoice platform requires a phone number to sign in, we found that any number entered resulted in a successful login. Once logged in, the page requests credit card information so that the e-invoice can be linked with the credit card. This lure is effective because e-invoices in Taiwan are eligible for a government-run lottery, and residents routinely retain their invoices in the hope of winning a prize. Figure 2: The fake platform that requires phone number to sign in Our research shows that the phishing page performs basic validation of the credit card information. Notably, the error messages shown for invalid input are displayed in Simplified Chinese. Figure 3: Simplified Chinese error messages After the credit card information is submitted, the page redirects to a second page requesting two-factor authentication (2FA) information. We assess that this data is likely synchronized to the phishing kit's backend server in near real time. Figure 4: The page requesting 2FA authentication 3. Relations to Darcula Our technical analysis of the phishing kit’s source code reveals that the victim data is encrypted with the Rabbit algorithm. The algorithm has been previously documented in the Darcula analysis.[2] Specifically, we identify a file app/chunk/DgZYu39z.js that contains an encryption and decryption mechanism sharing the same structure as the Darcula phishing kit. Therefore, we assess with high confidence that the campaign was deployed using the Darcula phishing kit. Notably, the actor may have used AI during development, as we identified numerous Simplified Chinese strings along with emoji characters in the source code. Footnotes [1] Korea University https://www.korea.ac.kr/sites/ko/index.do [2] Exposing Darcula: a rare look behind the scenes of a global Phishing-as-a-Service operation https://www.mnemonic.io/resources/blog/exposing-darcula-a-rare-look-behind-the-scenes-of-a-global-phishing-as-a-service-operation

How to Turn SEMI E187 Requirements into an Equipment Security Assessment Process
SEMI E187 establishes a cybersecurity baseline for semiconductor manufacturing equipment and defines the security capabilities equipment should have before entering a wafer fabrication facility. However, for many equipment suppliers and semiconductor manufacturers, the greatest challenge is not understanding the standard but translating its requirements into routine security assessment procedures. When assessments still rely on manually reviewing documents and checking configurations item by item, the process becomes time-consuming and difficult to perform consistently. Establishing a repeatable and measurable equipment security assessment process is therefore essential to implementing SEMI E187 effectively. Step 1: Build a Comprehensive Equipment Asset Inventory Effective security management begins with a clear understanding of the equipment and its assets. Start by identifying the equipment’s operating system versions, installed software, firmware versions, and network services. Confirm whether each component is still supported by its original vendor and establish a complete asset inventory as the foundation for subsequent risk assessments. Step 2: Assess Compliance with SEMI E187 Requirements After completing the asset inventory, assess the equipment against the core requirements of SEMI E187, including: Whether the operating system is still supported and regularly updated Whether network communications use encryption Whether unnecessary ports and services have been disabled Whether vulnerability remediation and malware protection capabilities are in place Whether account, privilege, and access controls have been properly implemented Whether complete logs are retained for auditing purposes Together, these controls constitute the fundamental security capabilities equipment should have before deployment and serve as important evidence during SEMI E187 validation. Step 3: Replace Manual Judgment with Automated Assessments In practice, many risks cannot be verified through documentation alone. For example: Has the operating system reached the end of support? Are default accounts still in use? Is HTTP traffic transmitted without encryption? Are high-risk ports such as VNC port 5900 exposed? Do communications lack encryption or authentication? Relying entirely on manual verification increases the likelihood of omissions and makes it difficult to maintain consistent assessment standards. Automated assessment tools can directly inventory equipment configurations, correlate findings with vulnerability intelligence, and convert previously ambiguous risks into measurable assessment results. This significantly improves both efficiency and accuracy. Step 4: Establish Risk Classification and Reporting Equipment assessments should not produce only a “pass” or “fail” result. Organizations should classify identified weaknesses according to severity and summarize them using risk levels such as Critical, High, Medium, and Low. Reports should also document remediation status, Windows hotfixes, software and firmware versions, and compliance gaps. This creates a structured record that can support audits, remediation planning, and management decision-making. Step 5: Move from One-Time Assessments to Continuous Management The purpose of SEMI E187 is not merely to complete a one-time validation. It is to establish ongoing cybersecurity governance for semiconductor manufacturing equipment. New risks may emerge throughout equipment delivery, deployment, production, and maintenance due to software updates, configuration changes, or newly disclosed vulnerabilities. Organizations should therefore establish periodic assessments, continuous monitoring, and incident response mechanisms. Equipment security should become part of routine operational management rather than a temporary activity conducted only before validation. Strengthen Cyber Resilience from Assessment to Protection SEMI E187 provides a common language for equipment cybersecurity, but its real value comes from converting the standard into an actionable assessment process. By integrating asset inventory, configuration assessment, vulnerability analysis, and continuous monitoring, organizations can improve validation efficiency while establishing an equipment security management framework that is measurable, traceable, and continuously improved. When security assessments become part of daily operations, SEMI E187 is no longer simply a compliance requirement. It becomes an important foundation for strengthening the resilience of the semiconductor supply chain. Is Your Equipment Compliant with SEMI E187? Whether you are preparing for SEMI E187 validation or seeking a faster way to understand the cybersecurity posture of your equipment, TeamT5 can help you establish an equipment security assessment process aligned with SEMI E187. Through automated asset inventory, vulnerability analysis, configuration assessment, and compliance reporting, TeamT5 helps reduce the cost of manual inspections while improving the efficiency and consistency of pre-deployment equipment assessments. Discover ThreatSonar Plus and learn how to transform SEMI E187 requirements into a sustainable equipment security management process. Notes This article references the SEMI E187 standard for educational and explanatory purposes only. The copyright of the standard belongs to SEMI, Semiconductor Equipment and Materials International. Official SEMI E187 requirements and interpretations should be based on the latest version published by SEMI.

How to Prepare for SEMI E187 Validation: An Essential Checklist for Equipment Suppliers
As cybersecurity requirements across the semiconductor supply chain continue to rise, SEMI E187 is becoming an increasingly important standard for both equipment suppliers and semiconductor fabs. For equipment manufacturers, E187 is not simply about passing a validation process. It demonstrates that equipment has essential cybersecurity capabilities in place before delivery, helping reduce deployment risks across the supply chain. How should equipment suppliers prepare for SEMI E187 validation? What Does SEMI E187 Validation Focus On? SEMI E187 focuses on the cybersecurity capabilities of fab equipment. It applies primarily to Windows- or Linux-based computing devices embedded in the equipment. The standard requires suppliers to provide relevant cybersecurity information and enables fabs to verify whether the equipment meets established security baselines. Key assessment areas include operating system security, network security, endpoint protection, access control, and logging. SEMI E187 Validation Checklist 1. Operating System Management Confirm that the operating system used by the equipment is still supported by the original vendor and has not reached end of life (EOL). Establish comprehensive patch and update management procedures to prevent unsupported or unmaintained operating systems from remaining in use. 2. Network Security Configuration Verify that the equipment uses encrypted communications and inventory all enabled network services and ports. High-risk services such as Telnet and FTP should be disabled. Only essential communication protocols should remain enabled to minimize the equipment’s attack surface. 3. Endpoint Protection Establish a vulnerability remediation process, confirm that the equipment has undergone malware scanning, and ensure that appropriate anti-malware protection is available. System configurations should also be hardened by restricting USB usage, disabling unnecessary services, and limiting local software installation privileges. 4. Account and Privilege Management Disable default accounts, establish a password policy, and avoid the use of shared accounts. Access privileges should be assigned according to user roles to ensure that all access to the equipment can be attributed and audited. 5. Logging and Audit Capabilities The equipment should retain comprehensive logs covering login activity, configuration changes, system errors, and other relevant events. These logs provide critical evidence for future audits, incident investigations, and compliance verification. Documentation Alone Is Not Enough—Equipment Security Must Be Verifiable Many organizations assume that providing the necessary documentation is sufficient to complete the validation process. In practice, however, SEMI E187 places greater emphasis on whether the equipment has cybersecurity capabilities that can be independently verified. For example: Does the equipment contain known vulnerabilities? Are default accounts still enabled? Are high-risk ports exposed? Does the equipment use unencrypted communications? Relying entirely on manual verification can be time-consuming and may leave critical risks undetected. As a result, a growing number of equipment suppliers are introducing automated assessment tools. Through asset inventory, vulnerability correlation, configuration assessments, and compliance reporting, organizations can transform processes that previously depended on manual judgment into measurable and traceable assessment workflows. This improves both the efficiency and consistency of SEMI E187 validation. Conclusion The purpose of SEMI E187 is not to create additional burdens for businesses. It is intended to establish a common cybersecurity baseline for semiconductor manufacturing equipment. For equipment suppliers, implementing a standardized assessment process at an early stage can: Improve validation efficiency Reduce supply chain risks Strengthen customer confidence in equipment security Establish a foundation for ongoing equipment cybersecurity governance Need to meet SEMI E187 compliance requirements within a limited timeframe? Contact TeamT5 to learn how ThreatSonar Plus can help your organization establish an automated cybersecurity assessment process for semiconductor equipment. Disclaimer This article references the SEMI E187 standard and is intended solely for educational and explanatory purposes. Copyright for the standard belongs to SEMI—Semiconductor Equipment and Materials International. Official SEMI publications should be regarded as the authoritative source for SEMI E187 requirements and interpretations.
