TwoSail Junk is a Chinese-speaking threat cluster associated with a Hong Kong-focused watering-hole operation observed in early 2020. The group is known for delivering a full remote iOS exploit chain and the modular LightSpy surveillance implant, indicating an espionage-oriented campaign centered on mobile-device compromise and victim monitoring. Activity suggests targeting of users in Hong Kong, with additional observed victim interest from Macau. The actor used compromised or attacker-controlled web content to lure victims, including posting links in forum threads and creating new discussion topics to drive traffic to exploit infrastructure. The operation was assessed to include support for Android implants and likely tooling for Windows, Linux, and macOS in addition to iOS, indicating a broader cross-platform surveillance objective beyond a single mobile platform. LightSpy is characterized as a modular surveillance framework, consistent with post-compromise collection and monitoring. Infrastructure associated with the cluster was reported primarily in Hong Kong, with additional hosting presence in Singapore and Shanghai. The actor has been assessed as a low-to-mid capability espionage operator. No widely established public aliases beyond TwoSail Junk are supported here.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.