Yellow Nix is a apt_group tracked by ThreatCluster. Linked intelligence reporting has not yet been indexed for this entity.
Yellow Nix is an APT actor observed in targeted campaigns against government and critical infrastructure sectors. It uses tailored modular malware implants and credential-dumping techniques to establish footholds, followed by post-exploitation and data exfiltration, making it a persistent espionage threat with evolving toolchains.