CardinalLizard is a Chinese-speaking cyber-espionage activity cluster assessed with moderate confidence as a distinct threat actor active since at least 2014. The group has been associated with targeted intrusions against businesses, with observed victimology including organizations in the Philippines, Russia, Mongolia, and Malaysia. Infrastructure overlap with Roaming Tiger and PlugX-related activity suggests tradecraft or operational connections within the broader Chinese-speaking intrusion ecosystem, but CardinalLizard is tracked as a separate collection of activity. The actor’s operations are consistent with espionage-oriented targeting of corporate entities. Reported activity indicates sustained regional interest in parts of Asia as well as Russia. High-confidence public reporting directly supports business-sector targeting and Chinese-speaking operational characteristics; additional malware or intrusion-stage details beyond those overlaps are not sufficiently established for stronger characterization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Active in the region; generally described as less technically advanced and focused on regional government/military targets.
CardinalLizard is a Chinese-speaking group targeting businesses in Asia and Russia, using custom malware with anti-detection and anti-emulation techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.