玫瑰黑客 is a Chinese-speaking cybercriminal group publicly accused of conducting distributed denial-of-service attacks for extortion. Reporting from 2009 portrays the group as an organized operation focused on disrupting victims’ online services through repeated DDoS activity and then leveraging that disruption for financial gain. The group was also alleged to offer illegal ancillary services related to online game private-server activity. The actor’s documented behavior centers on DDoS-based coercion rather than advanced intrusion tradecraft. Reported operations involved repeated service disruption against websites, causing prolonged slowness or outages and resulting in business impact on victims. Available information supports characterization of the group as using DDoS as both an attack mechanism and an extortion pressure tactic. No high-confidence evidence in the available material establishes broader intrusion capabilities such as credential theft, persistence, lateral movement, or espionage activity. Known reporting links the group to attacks against multiple Chinese-language websites and describes subsequent law-enforcement action in China, including investigation and disruption of the group’s online presence. The dominant assessed motivation is financial gain through cyber extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.