Worok is a cyberespionage threat actor assessed to be aligned with Chinese state interests. The group is associated with long-term intelligence collection operations and has been linked to shared espionage tooling including PhantomNet, HDMan, and Sonifake. Reporting has also associated the PowHeartBeat backdoor with Worok, and some research has noted possible ties or overlaps with TA428. Worok’s operations are characterized by stealthy persistence and post-compromise espionage activity rather than disruptive or financially motivated objectives. Observed tradecraft includes use of backdoors and shared espionage malware, persistence mechanisms, reconnaissance inside victim environments, credential theft, and exfiltration of sensitive information. In broader Chinese state-sponsored intrusion reporting, tooling overlaps connected to Worok have appeared in campaigns targeting government entities and collecting politically, militarily, and technically valuable information. At high confidence, Worok should be understood as a China-linked espionage actor that participates in the broader ecosystem of Chinese intrusion sets sharing malware, infrastructure patterns, and operational techniques. Public reporting indicates overlap with other Chinese clusters rather than a cleanly isolated toolkit, so some activity may be difficult to distinguish from related actors or subgroups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyberespionage group referenced because PowHeartBeat used in Cluster Alpha has been attributed to Worok.
Espionage activity leveraging shared toolsets (HDMan, PhantomNet, Sonifake); report notes inconsistent third-party attributions around these tools.
Cyberespionage group referenced due to attribution of PowHeartBeat and possible ties to TA428.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.