Autumn Dragon is a China-nexus cyber-espionage threat actor conducting targeted intelligence-collection operations against government, media, and news organizations in Southeast Asia, including Laos, Cambodia, Singapore, the Philippines, and Indonesia. The group has used spear-phishing attachments exploiting the WinRAR path-traversal vulnerability CVE-2025-8088 for initial access. Its multi-stage Windows intrusion chain employs legitimate applications for DLL side-loading, PowerShell and command-shell execution, and persistence through Registry Run Keys, Startup Folder artifacts, and scheduled tasks. Autumn Dragon deploys backdoors that use Telegram and HTTPS-based communications, conducts host and process discovery, queries the registry, collects screenshots, and exfiltrates sensitive information. The operation demonstrates an emphasis on stealthy, sustained access and long-term intelligence collection rather than disruptive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Autumn Dragon is exploiting a WinRAR vulnerability to deploy a backdoor that uses Telegram for command and control.
Autumn Dragon is a Chinese-nexus APT targeting government and media organizations.
China-nexus espionage group targeting government and media/news in Southeast Asia using email-delivered malicious archives exploiting a WinRAR path traversal vulnerability.
Autumn Dragon is conducting targeted espionage campaigns against government, media, and news sectors in Southeast Asia using spear-phishing, WinRAR exploits, DLL side-loading, and multi-stage malware delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.