Storm-2077, also tracked as TAG-100 and UNK_ColtCentury, is a China-aligned cyber espionage threat cluster associated with targeted social-engineering activity against Taiwan’s semiconductor ecosystem. The actor has been observed targeting legal personnel at Taiwanese semiconductor organizations, using benign conversation-starter emails and trust-building outreach as a precursor to malware delivery. Reported follow-on payloading was assessed as likely intended to deploy the SparkRAT remote access trojan. The cluster’s activity fits a broader pattern of Chinese state-sponsored collection against strategically important semiconductor organizations and related entities, with the apparent objective of gathering intelligence relevant to technology development, supply chains, business operations, and sector strategy. High-confidence reporting links the actor to phishing-based initial access and subsequent post-compromise remote access via SparkRAT. Known aliases include TAG-100 and Storm-2077.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UNK_ColtCentury is a Chinese APT that targeted legal personnel at Taiwanese semiconductor companies with phishing emails, likely leading to SparkRAT backdoor infections.
Engaging in trust-building email campaigns targeting legal personnel in Taiwanese semiconductor organizations to deliver Spark RAT.
China-aligned cluster observed sending benign 'conversation starter' emails to legal personnel at a Taiwanese semiconductor organization, assessed as pretexting to enable follow-on malware deployment (likely SparkRAT).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.