Tianwu is a China-linked advanced persistent threat intrusion set associated with espionage activity. Public reporting links the group to the use of Pangolin8RAT and custom Cobalt Strike Beacon tooling, and describes ongoing evolution of that malware stack. Tianwu has been observed targeting the transportation sector, including a Taiwanese rail-transportation company, indicating an interest in organizations with operational and strategic value. The actor’s tradecraft includes use of remote access malware and post-compromise tooling consistent with sustained access and follow-on operations. Based on the available high-confidence information, Tianwu is best characterized as a Chinese-linked espionage actor focused on covert intrusion and post-exploitation rather than ransomware or disruptive extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-linked APT associated with Pangolin8RAT and a custom Cobalt Strike Beacon; uses a loader chain (CoreX Loader via regsvr32.exe) to decrypt and load payloads in-memory, leverages WebDAV (Nutstore) and HTTPS header/cookie manipulation for C2 concealment, and implements multiple evasion/anti-forensics improvements.
China-associated intrusion set using Pangolin8Rat to target a Taiwanese rail transportation company; assessed as plausible prepositioning related to Taiwan contingency planning.
The content references Tianwu in the context of ongoing development/evolution of its tooling, specifically Pangolin8RAT and a custom Cobalt Strike Beacon.
Associated with use/evolution of Pangolin8RAT and a custom Cobalt Strike Beacon (implying ongoing development and deployment of bespoke tooling).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.