TA428 is a Chinese state-linked cyberespionage threat actor, also referred to in reporting as Colourful Panda, BRONZE DUDLEY, and Vicious Panda. Multiple sources in the provided content associate TA428 with Chinese origin or Chinese government sponsorship. TA428 has targeted government, technology, defense, and critical infrastructure organizations in China, as well as government and public-sector entities in East and Southeast Asia. Reported victim geographies and targeting include East Asian government agencies, Southeast Asian and Russian targets, Mongolia, Vietnam, and military-industrial and public institutions in Belarus, Russia, Ukraine, and Afghanistan. The group has been linked to Operation LagTime IT, in which spear-phishing emails delivered malicious RTF documents exploiting Microsoft Equation Editor vulnerabilities including CVE-2018-0798. In that activity, TA428 used Cotx RAT and Poison Ivy, and conducted post-compromise lateral movement with EternalBlue. Kaspersky-linked reporting in the content also ties TA428 to campaigns using spear-phishing documents exploiting CVE-2017-11882 to deploy PortDoor, followed by redundant backdoors, credential theft, network scanning, Ladon-based lateral movement, DLL hijacking, process hollowing, domain controller compromise, and exfiltration of encrypted ZIP archives. Malware and tooling attributed to or associated with TA428 in the content include ValleyRAT, Tmanger, PhantomNet, SManager, DOWNTOWN, Cotx RAT, Poison Ivy, PortDoor, nccTrojan, Logtu, DNSep, and Mail-O. Tmanger is described as a modular RAT with SetUp, MloadDll, and Client components, RC4-encrypted C2, service or Run-key persistence depending on privileges, and capabilities including process execution, file operations, keylogging, and screen capture. PhantomNet/SManager/DOWNTOWN is described as a modular backdoor capable of collecting victim information and installing plugins; reporting also notes plugin-based functionality that may support credential theft and lateral movement. Mail-O is presented as a PhantomNet/SManager variant associated with TA428. The content also links TA428 to supply-chain activity. ESET reported trojanized installers on the Vietnam Government Certification Authority website delivering PhantomNet/SManager, and separately documented Operation StealthyTrident in Mongolia, where trojanized Able Desktop installers and a likely compromised update mechanism delivered HyperBro, Korplug, and later Tmanger. The content notes uncertainty in some Mongolia-related attribution, including overlap with LuckyMouse/APT27 and ShadowPad infrastructure. TA428 has also been associated with Royal Road-generated RTF lures and grouped with East Asia-focused operators targeting Russia, Korea, and Japan. Positive Technologies reporting cited in the content notes a relationship between Space Pirates and TA428, including co-residence on infected systems and possible sharing of tools, infrastructure, or access, but does not present them as the same actor. Overall, the provided content characterizes TA428 as a long-running Chinese espionage actor using spear phishing, supply-chain compromise, DLL side-loading, modular backdoors, credential theft, lateral movement, and persistent multi-stage malware to support intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
攻撃者はEternal Blueを悪用して同一ネットワーク上のいくつかのホストに移動することに成功すると、そのうちの1つのホスト上で興味深いマルウェアを動かし始めました。
Attackers relied on Microsoft Equation Editor exploit CVE-2018-0798 to deliver a custom malware that Proofpoint researchers have dubbed Cotx RAT. Additionally... the malicious RTF attachments exploited vulnerabilities in the Microsoft Equation Editor, specifically CVE-2018-0798, before downloading subsequent payloads.
74 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced Chinese threat actor previously attributed with PhantomNet malware that overlaps with tooling seen in Cluster Alpha.
Chinese-linked espionage actor referenced due to attribution overlaps with Cluster Alpha malware including PhantomNet/DOWNTOWN and possible ties to Worok.
Referenced as a group previously associated with deploying ValleyRAT and targeting government, technology, defense, and critical infrastructure entities in China; not directly attributed as the actor behind this specific campaign.
China-linked threat actor referenced for prior attribution of the Ladon post-exploitation framework, which is also used in the described intrusions (as a lateral movement/scanning tool).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.