Skip to main content
Mallory
2 malware families

TALONITE

Also known asTALONITE

TALONITE is a threat activity group tracked by Dragos since July 2019. Its operations have focused on initial access compromises in the U.S. electric sector. Reported victimology also includes electric utilities in Japan and Taiwan, and its infrastructure is described as almost exclusively based in East Asia. TALONITE primarily uses spearphishing with malicious documents or executables for initial access, including engineering-themed lures designed to exploit trust. The group uses two custom multi-component malware families, LookBack and FlowCloud, and also abuses legitimate binaries or modifies legitimate binaries to add malicious functionality. Dragos describes TALONITE as blending tactics and using a mix of adversary-owned and compromised infrastructure, making the activity difficult to track and contain. The described ICS impact includes initial access, information gathering, and enabling further operations within the electric sector. Dragos reported behavioral overlap with the China-linked APT10 group, but stated it could not definitively attribute TALONITE to APT10. No additional aliases or sub-groups were provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • energy
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.