Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
4 malware families

REF5961

Also known asREF5961

REF5961 is an intrusion set identified by Elastic Security Labs and assessed with confidence as China-nexus, state-sponsored, and espionage-motivated. Elastic reported REF5961 targeting the Foreign Affairs Ministry of an ASEAN member state and disclosed three malware families associated with the intrusion set: EAGERBEE, RUDEBIRD, and DOWNTOWN (also referred to as PhantomNet). BLOODALCHEMY, an x86 backdoor discovered as shellcode injected into a signed benign process, is also described as part of the REF5961 intrusion set. Elastic linked REF5961 to previously reported REF2924 activity through co-resident malware, overlapping infrastructure, and execution-flow similarities, and noted overlaps with reporting on LuckyMouse/APT27/Emissary Panda and TA428/Colourful Panda/BRONZE DUDLEY. Sophos later reported overlaps between its Cluster Alpha activity in the Crimson Palace campaign and public reporting on REF5961, including use of EAGERBEE, RUDEBIRD, and DOWNTOWN/PhantomNet. Sophos assessed Crimson Palace with high confidence as Chinese state-sponsored and noted overlaps with REF5961, but did not attribute all activity to a single known actor. Observed tradecraft includes DLL sideloading, service-based persistence, lateral movement, reconnaissance, and use of multiple backdoors for persistent command and control. RUDEBIRD was observed launched from a path resembling a Sysinternals utility, with a parent process of w3wp.exe consistent with exploitation of an unpatched Microsoft Exchange vulnerability, and used PsExec for SYSTEM execution and lateral movement. EAGERBEE supports forward and reverse C2, proxy awareness, optional SSL, and in-memory execution of downloaded PE payloads. DOWNTOWN is a modular plugin-based implant aligned with SManager/PhantomNet. BLOODALCHEMY supports persistence via service, registry Run key, scheduled task, or COM interfaces; process injection; and communications over HTTP, named pipes, or sockets. Elastic assessed with high confidence that EAGERBEE and RUDEBIRD were operated by the same tasking authority or organizational umbrella based on shared infrastructure patterns, hosted-by-bay[.]net subdomains, coordinated service enablement windows, and TLS artifacts. The reporting describes REF5961 as a developing and maturing intrusion set targeting ASEAN members.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics30 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0002
Execution
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1559
Inter-Process Communication
T1559.001
Component Object Model
T1574
Hijack Execution Flow
T1574.001×2
DLL
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
4 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1055
Process Injection
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1055
Process Injection
T1574
Hijack Execution Flow
T1574.001×2
DLL
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1090.001
Internal Proxy
T1105
Ingress Tool Transfer
IOCS

Observables

18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

sophos threat researchNews
Jan 1, 2026
Operation Crimson Palace: Sophos threat hunting unveils multiple clusters of Chinese state-sponsored activity targeting Southeast Asian government | SOPHOS

Chinese-nexus espionage actor referenced because Cluster Alpha overlaps in malware and C2 infrastructure, including use of EAGERBEE, RUDEBIRD, and PhantomNet/DOWNTOWN against a Southeast Asian foreign affairs target.

Read more
sophos threat researchNews
Jun 5, 2024
Operation Crimson Palace: Sophos threat hunting unveils multiple clusters of Chinese state-sponsored activity targeting Southeast Asian government | SOPHOS

Chinese-nexus intrusion set referenced for overlap with Cluster Alpha through shared malware families and C2 infrastructure, previously reported targeting an ASEAN member’s foreign affairs ministry.

Read more
elastic security labsNews
Oct 13, 2023
Disclosing the BLOODALCHEMY backdoor - Elastic Security Labs

Intrusion set associated with the BLOODALCHEMY backdoor, which uses DLL sideloading, shellcode injection, multiple persistence mechanisms, and several communication options. The tooling appears modular and still in active development.

Read more
elastic security labsNews
Oct 4, 2023
Introducing the REF5961 intrusion set - Elastic Security Labs

State-sponsored, espionage-motivated intrusion set targeting governments and multinational government organizations in Southern and Southeastern Asia, including an ASEAN foreign affairs ministry environment. Associated with new malware families EAGERBEE, RUDEBIRD, and DOWNTOWN, and assessed as a China-nexus actor.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping14

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables18

Domains, IPs, and hashes tied to this actor, refreshed continuously.