SneakyChef is a Chinese-speaking cyber-espionage threat actor associated with malware operations targeting government entities across Asia and the EMEA region. The actor has been linked to the deployment of SugarGh0st malware and is also associated with SpiceRAT activity. Reporting further ties an updated SpiceRAT variant to Chinese-speaking threat activity, reinforcing assessment of SneakyChef as a China-nexus espionage operator. SneakyChef’s known victimology centers on government organizations, indicating an intelligence-collection mission rather than financially motivated intrusion activity. The actor has been referenced in connection with campaigns against public-sector targets in Asia and EMEA, consistent with broader regional espionage targeting patterns seen among China-aligned intrusion sets. Observed tradecraft includes use of remote access tooling capable of downloading and executing additional binaries and arbitrary commands on compromised systems, enabling flexible post-compromise operations. Based on the malware functionality attributed to the actor, SneakyChef demonstrates post-exploitation capability and supports follow-on payload delivery and remote command execution. No high-confidence evidence in the supplied facts supports ransomware or extortion activity by this actor. SneakyChef is also written as sneakychef. No additional high-confidence subgroup information is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only because SpiceRAT has been attributed to this actor, serving as background context for SilkParasite attribution.
CTI Roundup: Busy Days for Threat Actors ONNX Store, Boolka, & SneakyChef | Tanium
China-aligned actor targeting government entities in Asia and EMEA using SugarGh0st malware.
China-aligned actor targeting government entities in Asia and EMEA using SugarGh0st malware per excerpt.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.