SweetSpecter is a suspected China-based cyber-espionage threat actor, publicly tracked by Palo Alto Networks as TGR-STA-0043. Active since at least 2023, it has targeted government and political entities in Asia, the Middle East, and Africa, and conducted spear-phishing against OpenAI employees and governments internationally. In a 2024 campaign, SweetSpecter impersonated ChatGPT users seeking support and delivered SugarGh0st RAT through malicious attachments. The attempted compromise of OpenAI personnel was prevented before reaching corporate inboxes. SweetSpecter has used generative-AI services to support reconnaissance, vulnerability research, scripting, code debugging, social-engineering development, and attempts to evade detection. Its observed research included vulnerable software versions, public-facing content-management systems, known vulnerabilities, internet-wide scanning, web-shell deployment, and potential targeting of automotive infrastructure. The group’s operations and targeting are consistent with an espionage-focused mission.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted offensive-cyber support activity using AI and targeted OpenAI employees through spear-phishing delivering SugarGh0st RAT.
Experimenting with and integrating generative-AI services into operations, specifically for reconnaissance, vulnerability research, and scripting.
Chinese state-sponsored threat actor using LLMs for advanced post-compromise commands and spear-phishing, including targeting OpenAI employees.
China-linked cyber-espionage activity using spear-phishing with malicious ZIP attachments to deliver SugarGh0st RAT; leveraged ChatGPT for reconnaissance, vulnerability research, scripting, and social-engineering content generation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.