Luckycat is a Chinese cyber campaign/threat actor identified by Trend Micro in March 2012. Reported targeting includes U.S.-based activists and organizations, Indian and Japanese military research entities, and Tibetan activists. Additional reporting cited in the provided content links LuckyCat malware to Chinese APT activity targeting the international Tibetan community, including an Android APK/RAT variant reported by Talos Intelligence in January 2019. The content also notes infrastructure overlap between historic malware delivered in phishing campaigns targeting Tibetan civil society and LuckyCat malware, and later overlap with ExileRAT-associated activity. LuckyCat is therefore associated in the provided reporting with phishing-led intrusion activity and malware operations focused in part on Tibetan targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked cyber-espionage campaign targeting activists and military research organizations, including Tibetan activists and Indian/Japanese military research, for intelligence collection.
Cyber-espionage campaign targeting activists and military research organizations, including Tibetan activists and Indian/Japanese military research, consistent with intelligence collection objectives.
China-attributed cyber-espionage campaign targeting activists and military research entities, including Tibetan activist communities and military research in India and Japan.
China-linked cyber-espionage campaign targeting activists and military research entities, including Tibetan activists and Indian/Japanese military research, for intelligence collection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.