BrazenBamboo is a Chinese state-affiliated threat actor assessed to function as a private enterprise supporting governmental surveillance operations. The group has been linked to the development of the malware families DEEPDATA, DEEPPOST, and LIGHTSPY, and its tooling appears to be used by multiple governmental operators rather than exclusively by a single intrusion team. BrazenBamboo has been associated with modular post-exploitation capabilities focused on large-scale collection of sensitive information from compromised devices, supported by backend infrastructure for data analysis, operator management, and related surveillance functions. BrazenBamboo’s tooling demonstrates strong emphasis on credential theft, post-compromise collection, and exfiltration. DEEPDATA is a Windows modular post-exploitation framework with plugins for harvesting credentials from numerous applications and services, collecting chat data, recording audio, and extracting browser and Wi-Fi information. The actor weaponized a zero-day credential disclosure vulnerability in Fortinet’s Windows FortiClient VPN software to steal VPN credentials from process memory, illustrating both post-exploitation tradecraft and the ability to operationalize previously unpatched vulnerabilities. DEEPPOST has been associated with exfiltration of stolen data, while LIGHTSPY is a multi-platform malware family with variants for Android, iOS, macOS, and Windows. Technical overlaps between DEEPDATA and LIGHTSPY include shared plugin logic, export naming conventions, and command-and-control infrastructure characteristics, indicating a common developer or tightly coordinated development ecosystem. Reported infrastructure associated with BrazenBamboo includes operator-facing services, plugin hosting, and platforms supporting email theft, proxy generation, and large-scale analysis of stolen information. The actor’s tooling and infrastructure have also been linked to domestic surveillance and law-enforcement-oriented use cases. Known aliases directly supported here are limited to BrazenBamboo.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.