Curious Gorge is a China-attributed cyber-espionage threat actor assessed to be linked to the People’s Liberation Army Strategic Support Force (PLA SSF). The group has been observed conducting campaigns against government and military organizations in Ukraine, Russia, Kazakhstan, and Mongolia, and has also targeted logistics and manufacturing entities across Ukraine, Russia, and Central Asia. Reported victimology includes Russian government organizations, Russian defense contractors and manufacturers, and a Russian logistics company, indicating an intelligence-collection focus that spans both state institutions and supporting industrial ecosystems. The actor’s operations have been associated with phishing and malware delivery activity tied to Ukraine war-related lures, consistent with broader state-backed collection efforts exploiting geopolitical events. Available reporting supports assessment of a sustained espionage mission focused on regional political, military, and supply-chain intelligence rather than financially motivated crime or disruptive ransomware operations. Publicly available information in this context does not establish a broader alias set or identified sub-groups for Curious Gorge beyond the name itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in passing in a multi-actor landscape summary.
Named activity cluster referenced in reporting on the Ukraine conflict.
Ongoing compromises and campaigns against government, military, logistics, and manufacturing targets in Ukraine, Russia, and Central Asia, including Russian government entities (e.g., Ministry of Foreign Affairs) and Russian defense contractors/manufacturers and a logistics company.
Conducted campaigns against government and military organizations using Ukraine war-related themes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.