Hellsing is a distinct cyber-espionage threat actor active in the Asia-Pacific region, particularly around South China Sea geopolitical interests. The group became notable after conducting an apparent APT-on-APT counterattack against Naikon operators, indicating both operational maturity and awareness of competing intrusion activity in the same target space. Hellsing has been observed targeting government, diplomatic, military, and ASEAN-related entities, with especially strong focus on Malaysia, the Philippines, and Indonesia. Additional victimology has included diplomatic organizations in the United States and older malware instances associated with India. Hellsing relies heavily on spear-phishing for initial access, typically using malicious archive attachments including RAR, ZIP, and password-protected 7ZIP files themed around government, military, diplomatic, and policy matters. Its malware includes custom backdoors identified as msger and xweber, along with supporting tools such as xrat, clare, irene, test, diskfilter, and xKat. These tools support remote access, victim profiling, proxy testing, file operations, and post-compromise host management. The group has also used utilities to terminate and remove malware belonging to rival threat actors, underscoring a willingness to operate in contested environments. Technical analysis has shown overlaps in infrastructure, protocol artifacts, and development lineage with other China-linked intrusion clusters including PlayfullDragon, GREF, Mirage, Vixen Panda, Cycldek, and Goblin Panda. Despite these overlaps, Hellsing is generally treated as a separate operation rather than a confirmed sub-group of those actors. Compilation-time patterns suggest operators worked primarily in the GMT+8 to GMT+9 time zone. Available evidence supports assessment of Hellsing as a China-linked espionage actor focused on regional political and strategic intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
32 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An activity cluster observed spear-phishing Naikon-related entities (including reportedly spear-phishing the Naikon group itself), indicating inter-APT conflict/‘payback’ operations in the South China Sea espionage ecosystem.
APT group active in the APAC region, especially the South China Sea area, conducting spear-phishing attacks with archive attachments containing backdoors such as msger and Xweber. It targeted government, diplomatic, and ASEAN-related entities, and notably retaliated against or targeted Naikon operators.
APT group mentioned as related/background comparison in Southeast Asia espionage discussion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.