Mandiant is a cybersecurity company, not a threat actor. In this context it is referenced as an attribution source assessing that at least one early exploitation cluster targeting Microsoft SharePoint on-premises vulnerabilities in July 2025 was China-aligned or China-nexus. No distinct threat actor name, alias set, or sufficiently specific actor profile is provided to support enrichment of a threat actor entity beyond that limited attribution statement.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Die Schwachstelle mit der Kennung CVE-2025-22457 erlaubt einem nicht authentifizierten Angreifer, Code auf verwundbaren Geräten auszuführen. Mit einem Wert von 9.0 wurde die Sicherheitslücke nach dem Common Vulnerability Scoring System als "kritisch" bewertet.
The Core Flaw CVE-2026-20245 affects the command-line interface of Cisco Catalyst SD-WAN Manager and stems from insufficient validation of user-supplied input. An authenticated local attacker can exploit it by uploading a crafted file to the affected system and consequently execute arbitrary commands as root.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.