A collective label for multiple state-sponsored cyber espionage groups attributed to China, Iran, North Korea, and Russia that exploited the Windows shortcut vulnerability CVE-2025-9491 over a period beginning in 2017. This is not a single coherent threat actor, but an umbrella reference to several government-backed intrusion teams from four different states. Reported activity centered primarily on espionage and information theft, with targeting that included government, financial, telecommunications, and energy organizations. Documented operations included spearphishing campaigns delivering malicious shortcut files, concealment of malicious commands within .LNK files to evade user inspection, and follow-on malware deployment including PlugX. Observed tradecraft also included DLL sideloading, persistence establishment, and command-and-control communications to support ongoing intelligence collection. Known examples associated with exploitation of this vulnerability include Chinese-affiliated activity such as UNC6384 targeting European diplomatic entities, as well as use by the espionage group XDSpy against Eastern European government targets. Because this designation aggregates multiple distinct state-backed groups rather than identifying one actor, aliases, sub-groups, origin, and targeting should be treated as collective rather than singular.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.