EvilOctal Security Team was a Chinese red-hacker era security group active in the broader ecosystem of Chinese hacker communities that emerged in the late 1990s and 2000s. Like several peer groups from that period, it appears to have combined a large public-facing membership or forum user base with a much smaller operational core. Reported figures indicate a peak of 9,562 members in 2006, while by 2010 the group listed 31 core members, underscoring the distinction between nominal community size and the smaller cadre responsible for substantive activity. The group differentiated among multiple internal roles, including think tank contributors, journal editors, operations and maintenance staff, a technical core team, decision-makers, and team executives. This structure indicates that EvilOctal functioned not only as a hacking collective but also as an organized community with editorial, administrative, and operational support functions. Within the Chinese red-hacker milieu, such groups typically relied on a limited number of technically proficient members for hands-on operations, while broader registrant populations participated primarily through community engagement rather than advanced offensive activity. EvilOctal Security Team is best understood as part of the formative generation of Chinese hacker organizations that helped shape China’s early cyber ecosystem. Available information supports its characterization as a community-centered security team with a defined core membership and technical component, but does not provide high-confidence evidence on specific victimology, operational campaigns, malware usage, or direct state tasking.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.