Operation Wocao is a cyber espionage intrusion set associated with post-compromise reconnaissance, credential access, lateral movement, data collection, and exfiltration in Windows enterprise environments. Observed tradecraft includes downloading additional payloads, extensive host and network discovery, recursive file and directory enumeration, process discovery, user and session enumeration on remote hosts, identification of privileged users, and collection of system time and disk or operating system details. The actor has used PowerShell extensively, including malicious PowerShell executed through scheduled tasks on remote systems, and has leveraged command-shell execution and native Windows utilities for discovery and operations. Credential-access activity includes enabling WDigest to facilitate recovery of credentials from memory. Execution and post-exploitation behavior includes spawning command interpreters, using native API functions such as CreateProcessA and ShellExecute after process injection, and exfiltrating files and directories of interest, including through the Xserver backdoor. Defense-evasion and anti-forensics behavior includes detecting security software and deleting logs and executables used during the intrusion. The overall pattern is consistent with a disciplined espionage-focused actor conducting interactive intrusions aimed at collecting information from targeted networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign activity included local network configuration discovery using ipconfig.
Campaign involving local disk discovery, hardware profiling, and OS version discovery across targeted networks.
Campaign involving remote session and user enumeration, including identification of privileged users.
Uses PowerShell on compromised systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.