Luckycat
Luckycat is the name Trend Micro gave to a Chinese cyber campaign disclosed in March 2012. Based on the provided content, the campaign targeted U.S.-based activists and organizations, Indian and Japanese military research entities, and Tibetan activists. No additional high-confidence details on tooling, specific TTPs, sub-groups, or further aliases beyond “Luckycat” are present in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked cyber-espionage campaign targeting activists and military research organizations, including Tibetan activists and Indian/Japanese military research, for intelligence collection.
Cyber-espionage campaign targeting activists and military research organizations, including Tibetan activists and Indian/Japanese military research, consistent with intelligence collection objectives.
China-attributed cyber-espionage campaign targeting activists and military research entities, including Tibetan activist communities and military research in India and Japan.
China-linked cyber-espionage campaign targeting activists and military research entities, including Tibetan activists and Indian/Japanese military research, for intelligence collection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.