Carderbee is a threat cluster associated with a supply-chain-style intrusion campaign that abused the Cobra DocGuard document security platform to deliver the PlugX backdoor. Public reporting links the cluster to trojanized or malicious software updates used to compromise roughly 100 systems, primarily in Hong Kong, with additional victims in other parts of Asia. The operation targeted multiple organizations rather than broad opportunistic victim sets, indicating selective intrusion activity. Carderbee is notable for weaponizing trusted software distribution mechanisms to gain initial access and establish persistent remote access through PlugX. PlugX is a long-running backdoor family frequently associated with Chinese intrusion activity, and Carderbee has been discussed in that context, although the cluster itself is best treated as a distinct tracked actor or activity set rather than conclusively attributed to a specific named group. The campaign has been described as using code-signed malware and compromised update channels, consistent with defense evasion and supply-chain compromise tradecraft. Known aliases are limited to Carderbee. High-confidence reporting supports its use of trojanized updates for initial access, deployment of a backdoor for post-compromise control, and targeting concentrated in Hong Kong and elsewhere in Asia. The available information supports an espionage-oriented assessment more strongly than financially motivated crime, but detailed victimology by sector and any formal state attribution remain limited in the currently available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A threat cluster observed using a trojanized version of Cobra DocGuard to deploy PlugX in attacks targeting organizations in Hong Kong and other Asian countries.
Carderbee is a Chinese APT group that conducted a supply chain attack via weaponized software updates, deploying PlugX backdoor, primarily targeting Hong Kong.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.