TA428 is a China-linked advanced persistent threat cluster associated with long-running cyberespionage operations across East and Southeast Asia and, in multiple investigations, against Russian and other Eurasian government and strategic-sector targets. The group has been linked by multiple researchers to Chinese state interests and is also tracked under aliases including Vicious Panda, Colourful Panda, and BRONZE DUDLEY. Reporting also notes relationships or overlaps with activity tracked as ThunderCats and with operations involving Space Pirates, though those overlaps do not establish full equivalence. TA428 is known for targeting government, foreign affairs, defense, military-industrial, technology, critical infrastructure, and public-sector organizations, with repeated victimology in Mongolia, Vietnam, Russia, China, and broader Southeast Asia. Documented campaigns include Operation LagTime IT, supply-chain compromise activity involving software used by Mongolian and Vietnamese government users, and spear-phishing-led intrusions against East Asian government entities. In some cases the actor has also been associated with targeting public institutions and research organizations in Belarus, Ukraine, and Afghanistan. The group uses a diverse malware ecosystem that includes Tmanger, PhantomNet or SManager, DOWNTOWN, ValleyRAT, Cotx RAT, PortDoor, Poison Ivy, Logtu, DNSep, nccTrojan, and malware overlaps involving EAGERBEE, RUDEBIRD, PowHeartBeat, and related loaders or plugins. TA428 tooling is often modular and supports plugin delivery, remote command execution, victim profiling, file operations, screen capture, keylogging, credential theft, and persistent command-and-control. Several TA428-associated malware families use misspelled exported functions such as Entery and service-oriented execution flows, and the actor has repeatedly relied on DLL sideloading and signed or legitimate binaries to launch payloads. Initial access has included spear phishing with malicious RTF or Word documents exploiting Microsoft Equation Editor vulnerabilities such as CVE-2018-0798 and CVE-2017-11882, as well as software supply-chain compromise and trojanized installers. Post-compromise behavior includes reconnaissance, credential theft, lateral movement using stolen credentials and exploitation tools, service and scheduled-task persistence, process injection, process hollowing, UAC bypass, and defense evasion through DLL hijacking, in-memory unhooking, and disabling or bypassing endpoint protections. TA428 has also been observed using EternalBlue for lateral movement and the Ladon framework for scanning, exploitation support, and network propagation. Operational objectives are consistently aligned with intelligence collection. Intrusions attributed to TA428 have involved long-term persistence, compromise of domain controllers and administrative infrastructure, collection of sensitive government, military, political, technical, and infrastructure information, and exfiltration of stolen documents through staged command-and-control channels. The overall pattern is that of a mature Chinese cyberespionage actor focused on strategic regional intelligence requirements.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
攻撃者はEternal Blueを悪用して同一ネットワーク上のいくつかのホストに移動することに成功すると、そのうちの1つのホスト上で興味深いマルウェアを動かし始めました。
Attackers relied on Microsoft Equation Editor exploit CVE-2018-0798 to deliver a custom malware that Proofpoint researchers have dubbed Cotx RAT. Additionally... the malicious RTF attachments exploited vulnerabilities in the Microsoft Equation Editor, specifically CVE-2018-0798, before downloading subsequent payloads.
74 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced Chinese threat actor previously attributed with PhantomNet malware that overlaps with tooling seen in Cluster Alpha.
Chinese-linked espionage actor referenced due to attribution overlaps with Cluster Alpha malware including PhantomNet/DOWNTOWN and possible ties to Worok.
Referenced as a group previously associated with deploying ValleyRAT and targeting government, technology, defense, and critical infrastructure entities in China; not directly attributed as the actor behind this specific campaign.
China-linked threat actor referenced for prior attribution of the Ladon post-exploitation framework, which is also used in the described intrusions (as a lateral movement/scanning tool).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.