Starchy Taurus is a China-nexus threat actor commonly associated with the Winnti umbrella and also referred to as Winnti Group and BARIUM. It is linked to the broader Chinese APT ecosystem and has been cited alongside other PRC-aligned groups that share operational infrastructure. The actor has been associated with use of the Winnti malware family, including Linux variants used in intrusions against cloud and Linux environments. Starchy Taurus has been observed abusing CHM files to conceal malicious payloads, including payloads implemented with PowerShell or JavaScript, reflecting defense-evasion tradecraft through deceptive file formats and staged execution. Reporting also places the actor within a shared Chinese operational infrastructure ecosystem used by other China-nexus groups, indicating overlap in infrastructure patterns while not necessarily implying identical operations. The group is assessed as part of the Chinese state-linked intrusion landscape and is primarily associated with espionage activity. Known aliases include Winnti and Winnti Group, with BARIUM also used in reporting for related activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Chinese threat actor within the same shared infrastructure ecosystem; no additional activity details provided in this content.
Referenced as a Chinese threat actor in the same infrastructure ecosystem as Phantom Taurus; no direct activity details provided in this content.
Referenced as a Chinese APT sharing an operational infrastructure ecosystem with Phantom Taurus; no specific campaign details provided here.
Referenced as a Chinese APT within the same shared infrastructure ecosystem (no direct activity described in this content).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.