NCPH, short for Network Crack Program Hacker, was a Chinese hacking group founded by Tan Dailin, also known as Wicked Rose and Withered Rose. The group emerged from China’s early nationalist hacker scene and is associated with the broader evolution of patriotic hackers into state-aligned cyber operators. NCPH became known for winning hacking contests, developing offensive tooling, and contributing to early Chinese malware development. The group is credited with creating the GinWui rootkit, described as one of China’s first domestically developed remote-access backdoors. NCPH members also collaborated on malware development with figures tied to later Chinese intrusion tooling, including work associated with the PlugX ecosystem. Historical reporting links Tan Dailin’s time in NCPH to collaboration with the developer known as whg, including development of remote-control software. NCPH is believed to have conducted intrusions against United States companies and government entities in 2006, reportedly using the GinWui rootkit together with numerous zero-day exploits. These operations have been described as unusually advanced for their time and as part of a broader pattern of Chinese state-directed cyber activity. Available reporting further indicates that Tan Dailin was noticed by the People’s Liberation Army, participated in PLA-affiliated training and competitions, and later became associated with Ministry of State Security-linked activity through APT41. In that context, NCPH is best understood as an early Chinese intrusion group situated at the intersection of underground hacking, tool development, and state-backed espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese hacking group founded by Tan Dailin that developed offensive tools including the GinWui rootkit and allegedly conducted intrusions against US companies and government entities on behalf of the PLA.
Hacking group referenced historically in connection with early remote-control malware development ("NCPH Remote Control Software") by individuals later tied to ShadowPad/PlugX ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.