TA413 is a China-aligned cyber-espionage threat actor focused primarily on Tibetan organizations, Tibetan dissidents, and the wider Tibetan diaspora. The group’s activity supports intelligence collection and surveillance of communities perceived as politically sensitive to Chinese state interests. TA413 has also targeted European diplomatic, legislative, policy, and economic organizations, including through COVID-19-themed lures, and has targeted officials in the United States and Europe. TA413 conducts low-volume, targeted spearphishing and watering-hole operations. It has impersonated Tibetan organizations and legitimate institutions to distribute malicious documents, trojanized browser extensions, and fake software-update pages. The group has exploited CVE-2022-30190 (Follina) in document-based attacks against the Tibetan community and has used Royal Road weaponized documents, including Microsoft Equation Editor exploitation, to deliver malware. Known TA413 malware includes Sepulcher, ExileRAT, FriarFox, and ScanBox. FriarFox is a malicious Firefox extension based on an open-source Gmail-notification tool that can access and manipulate Gmail messages, collect browser data, and retrieve follow-on reconnaissance tooling. Sepulcher is a remote-access trojan capable of host reconnaissance, file operations, and reverse-shell access; it establishes scheduled-task persistence and stores encrypted configuration data in the Windows registry. ScanBox has been used for browser and system reconnaissance, data collection, and keylogging. TA413 has also been associated with activity involving LuckyCat. The actor uses masquerading, tailored social engineering, credential and browser-data collection, persistence mechanisms, and command-and-control-based data exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed to the 2019 Holy Water watering-hole campaign, which compromised religious and charitable websites targeting Asian religious minorities to deliver the ScanBox framework and collect victim-system and browsing data.
Historically reported targeting of Tibetan organisations; referenced here due to overlaps in domain registration patterns and spoofing of Tibetan-themed infrastructure.
Named as one of several China-based threat actors observed using the ScanBox framework.
Exploited the Follina (CVE-2022-30190) MSDT RCE zero-day in phishing/lure-based attacks targeting the Tibetan diaspora.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.