Holy Water is a previously unidentified threat actor tracked for watering-hole and malware-delivery operations against Tibetan-interest targets. The actor was observed compromising or abusing Tibetan-interest websites to present fake Adobe Flash update lures and later resumed activity with a renewed toolset. Subsequent operations used a Go-based implant known as Godlike12 that leveraged cloud storage services for command and control, and later samples associated with the cluster included Telegram-controlled and Python-based implants derived from open-source tooling. The available reporting supports classifying Holy Water as an intrusion set focused on covert access and follow-on malware deployment rather than ransomware or destructive operations. Observed tradecraft includes watering-hole compromise, social-engineering-based initial access, use of staged implants for post-compromise control, and data theft-oriented espionage behavior. No high-confidence country-of-origin attribution is established in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Runs intrusions using Go-based and cloud/drive-controlled implants (Godlike12) and later-stage Python implants controlled via Telegram/open-source tooling, suggesting flexible C2 and post-compromise tooling.
Operates watering holes on Tibetan-interest websites, using fake Flash updates distributed via GitHub; evolving but relatively unsophisticated toolset leveraging multiple languages and cloud-based C2 (e.g., Google Drive).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.