Poison Vine, also tracked as 毒云藤, APT-C-01, and APT-Q-20, is a long-running Chinese-language cyber-espionage threat actor assessed in the supplied reporting as associated with Taiwan. Activity attributed to the group has been traced back to at least 2007, with public disclosure beginning in 2015. The actor primarily targets mainland China entities, especially government, military, defense, intelligence-related, and scientific research organizations, as well as higher-education institutions connected to research and national defense topics. Poison Vine is characterized by sustained credential-harvesting and intelligence-collection operations. Its campaigns have used spearphishing emails, phishing websites, watering-hole style attacks, and social-engineering lures themed around military affairs, cyber defense, civil-military fusion, recruitment, manuscript solicitation, and official notifications. The group has impersonated popular mainland email services, government portals, universities, enterprises, and consumer web applications to steal credentials and collect internal information. Some operations reused stolen internal notices from compromised mailboxes to improve lure credibility. The actor has operated multiple phishing frameworks, including LJFrame, LJFrame 2.0, LJFrame 3.0, CPFrame, and FAPPFrame. These frameworks supported credential capture, victim validation, redirection to legitimate services after submission, and infrastructure changes intended to hinder discovery. Reporting also links Poison Vine to malware delivery through malicious attachments and exploitation of CVE-2018-20250 in WinRAR ACE archives. Associated malware and post-compromise tooling have included custom loaders and backdoors as well as Cobalt Strike, Sliver, and tinyshell. Observed capabilities include credential theft, file discovery and exfiltration, remote command execution, process and drive enumeration, persistence via startup placement and autorun mechanisms, in-memory payload execution, and defense evasion such as anti-logging patching. The group has also been described as using publicly known N-day vulnerabilities and weak-password attacks against edge and embedded devices such as routers, cameras, smart-home devices, and firewalls to gain footholds or pivot into internal networks. Overall, Poison Vine is best understood as an espionage-oriented APT focused on long-term access, credential collection, and theft of sensitive internal information from mainland Chinese government, defense, military, and research targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
112 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
面向中国大陆政府/军工/科研等目标的长期情报窃取型APT活动:通过大规模仿冒社交软件/邮箱/政府与军工及高校网站实施钓鱼站与钓鱼邮件投递,自研Loader加载CobaltStrike/Sliver/TinyShell等远控与窃密载荷;同时利用公开N-day与弱口令攻击路由器、摄像头、智能家居、防火墙等设备作为跳板或内网渗透入口。
A long-running Chinese-language espionage group attributed with the 'Operation Rubia cordifolia' campaign, conducting large-scale phishing, credential theft, lure-based collection, and malware delivery against mainland Chinese targets for intelligence collection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.