REF5961 is a China-nexus, state-sponsored cyberespionage intrusion set first publicly documented in 2023. It has targeted government organizations, including the foreign affairs ministry of an ASEAN member state, and has been associated with Mongolia-focused activity against government entities or NGOs. REF5961 was observed co-resident with the separate REF2924 intrusion set and is assessed to operate under a Chinese state-aligned tasking authority. REF5961 uses the EAGERBEE, RUDEBIRD, DOWNTOWN, and BLOODALCHEMY malware families. EAGERBEE supports host reconnaissance, proxy-aware forward or reverse command-and-control, optional TLS, and in-memory execution of downloaded payloads. RUDEBIRD is an HTTPS backdoor used for host discovery, file and directory operations, process execution, and lateral movement with elevated privileges. DOWNTOWN is a modular implant associated through code and architectural similarities with PhantomNet/SManager and supports disk and file enumeration and manipulation. BLOODALCHEMY is a C-based backdoor deployed through DLL sideloading and shellcode injection; it supports service, scheduled-task, and autorun persistence, process injection, host reconnaissance, component replacement, and multiple communications mechanisms. The intrusion set has used signed or legitimate applications for DLL sideloading, dynamic API resolution, encrypted or obfuscated configuration data, in-memory payload execution, process injection, and infrastructure-management practices intended to complicate analysis. EAGERBEE and RUDEBIRD infrastructure and operational patterns indicate that their operators worked under the same tasking authority or organizational umbrella. Some tooling and victimology overlap with Chinese-linked clusters including LuckyMouse (APT27), TA428, and PhantomNet-related activity, but REF5961 is tracked as a distinct intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as the threat actor previously associated with BLOODALCHEMY, providing background attribution context rather than being the subject of this report.
Chinese-nexus espionage actor referenced because Cluster Alpha overlaps in malware and C2 infrastructure, including use of EAGERBEE, RUDEBIRD, and PhantomNet/DOWNTOWN against a Southeast Asian foreign affairs target.
Referenced as an intrusion set confirmed to use EAGERBEE.
Chinese-nexus intrusion set referenced for overlap with Cluster Alpha through shared malware families and C2 infrastructure, previously reported targeting an ASEAN member’s foreign affairs ministry.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.