TA428 is a Chinese state-aligned advanced persistent threat group focused on cyberespionage against government and strategically significant organizations, principally in East Asia. It is also known as Colourful Panda and BRONZE DUDLEY. The group has conducted Operation LagTime IT since at least 2019, targeting East Asian government agencies responsible for information technology, domestic and foreign affairs, political processes, scientific research, and economic development. Confirmed victimology includes Mongolian government and political entities, Russian defense- and aviation-related organizations, and Japanese organizations. TA428 commonly gains access through spearphishing emails carrying Royal Road weaponized RTF lures that exploit Microsoft Equation Editor vulnerabilities, notably CVE-2018-0798. Its operations have deployed Poison Ivy, Cotx RAT, Tmanger, nccTrojan (MsmRAT), Albaniiutas, and malware associated with the SManager/PhantomNet lineage. The group has used malicious Word add-ins for persistence, DLL search-order hijacking and DLL sideloading, Windows services, and Run-key persistence. Its malware supports host and network reconnaissance, remote shell access, file collection and transfer, screen capture, keylogging, process control, and encrypted command-and-control communications. During Operation LagTime IT, TA428 used credential-stealing tools, NetBIOS and vulnerability scanning, and exploitation of MS17-010 to move laterally. It deployed additional implants on compromised hosts, including through service-based execution and legitimate-application sideloading. TA428 activity is associated with Chinese state interests and is primarily espionage-motivated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
The lure document file is an RTF file generated by Royal Road RTF Weaponizer. Exploits CVE-2018-0798.
Used a tool to exploit MS17-010 for lateral movement. Scan Tool for MS17-010: ms17-010-m4ss-sc4nn3r v1.0. Exploit Tool for MS17-010: eternalblue.py.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
170 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced Chinese threat actor previously attributed with PhantomNet malware that overlaps with tooling seen in Cluster Alpha.
Chinese-linked espionage actor referenced due to attribution overlaps with Cluster Alpha malware including PhantomNet/DOWNTOWN and possible ties to Worok.
Referenced as a group previously associated with deploying ValleyRAT and targeting government, technology, defense, and critical infrastructure entities in China; not directly attributed as the actor behind this specific campaign.
Previously assessed as a possible user of EAGERBEE in attacks targeting Japanese organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.