POISON CARP is a China-aligned cyber-espionage threat actor associated with surveillance and intrusion activity targeting Tibetan and Uyghur communities, including diaspora organizations, activists, journalists, and institutions linked to these populations. The actor has been tied to campaigns consistent with Chinese state security interests and has been linked in multiple analyses to the Chinese contractor ecosystem, including reporting that tracks i-SOON as POISON CARP or identifies operational and organizational ties between i-SOON and POISON CARP activity. POISON CARP is best known for a 2018-2019 campaign against senior members of Tibetan organizations conducted through highly tailored WhatsApp social engineering. Operators posed as NGO workers, journalists, volunteers, and other trusted personas to deliver malicious links for one-click mobile exploitation. This activity is notable as the first publicly documented use of one-click mobile browser exploits against Tibetan groups. The campaign used both iOS and Android exploit chains and, in at least one case, combined exploit delivery with malicious Google OAuth consent phishing to obtain access to Gmail data. On Android, POISON CARP was associated with the MOONSHINE exploit-and-spyware framework. MOONSHINE used multiple Chromium and Android browser exploits, including n-day vulnerabilities and exploit code adapted from public research, to compromise devices through malicious links often delivered over messaging platforms. Successful exploitation installed Android surveillance tooling referred to by researchers as Scotch, supported by modular plugins that enabled collection of SMS messages, contacts, call logs, GPS location, camera images, microphone audio, screenshots, notifications, files, and shell command execution. Later reporting described MOONSHINE as an evolving Android surveillance platform still under active development and used against Tibetan and Uyghur targets, with delivery frequently relying on social engineering and links disguised as legitimate content. Some research indicates MOONSHINE may be shared across multiple Chinese-aligned intrusion sets, so not every MOONSHINE deployment can be attributed exclusively to POISON CARP. POISON CARP has also been linked to iOS exploitation and spyware deployment. Observed iOS activity used browser and privilege-escalation exploit chains against older iPhone versions and delivered spyware capable of exfiltrating device and application data, including location information, contacts, call history, SMS history, and data from communications applications. Researchers assessed overlaps between POISON CARP’s iOS tooling and campaigns previously reported against the Uyghur community, suggesting either the same operator or a closely coordinated group. Victimology strongly centers on ethnic minority and dissident communities viewed as sensitive by the Chinese state, especially Tibetans and Uyghurs. Targeting has included the Private Office of His Holiness the Dalai Lama, the Central Tibetan Administration, the Tibetan Parliament, Tibetan human rights groups, and related civil society figures. Tradecraft includes impersonation, spear-phishing via messaging apps, exploit delivery through malicious links, OAuth consent phishing, selective targeting, and modular mobile surveillance implants. Aliases include PoisonCarp, poisoncarp, and poison_carp. POISON CARP has sometimes been discussed alongside Earth Empusa or Evil Eye because of overlaps in targeting and some tooling or vendor-developed malware, but several analyses assess POISON CARP as a separate activity cluster rather than identical to Earth Empusa. It has also been mentioned in relation to Earth Minotaur because both used MOONSHINE against similar communities, though available reporting does not establish them as the same actor. Overall, POISON CARP represents a mobile-focused espionage operator within the broader China-linked surveillance ecosystem, distinguished by tailored social engineering, operational interest in Tibetan and Uyghur communities, and early documented use of one-click mobile exploitation in support of transnational repression and intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
Other exploits include what appears to be lightly modified versions of Chrome exploit code published on the personal GitHub pages of a member of Tencent’s Xuanwu Lab (CVE-2016-1646).
Exploit #2: Appears to be CVE-2016-5198, a bug publicly credited to Tencent’s Keen Security Lab via Trend Micro’s Zero Day Initiative and fixed in Chrome 54.0.2840.87.
Exploit #3: Appears to be CVE-2017-5030, a bug publicly credited to security researcher Brendon Tiszka.
Exploit #4: Appears to include a CVE-2017-5070 exploit published on Qixun Zhao’s Github account of Qihoo 360’s Vulcan Team.
Exploit #6: Appears to be CVE-2018-17463, a bug publicly credited to security researcher Samuel Groß.
3 more CVEs tied to this actor tracked in Mallory.
50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial offensive cyber contractor linked to the Chinese contractor ecosystem, developing and selling offensive cyber tools including spyware, phishing kits, and hardware implants to state customers such as the MSS, PLA, and local Public Security Bureaus.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity.
Conducted a mobile espionage campaign against Tibetan groups via tailored WhatsApp social engineering, delivering iOS and Android browser exploits, spyware, and in at least one case a malicious OAuth phishing application. The campaign overlaps with Uyghur-targeting activity and is likely linked to the same operator or a closely coordinated group behind the Google Project Zero and Volexity-reported campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.