Nylon Typhoon is a China-linked state-associated cyber espionage actor tracked by Microsoft. The group has been observed targeting foreign affairs entities globally, with activity specifically noted during June through December 2023. Reported targeting spans multiple regions, including Europe and South America, indicating an emphasis on diplomatic and international-relations intelligence collection rather than financially motivated crime or disruptive operations. Nylon Typhoon is part of Microsoft's broader "Typhoon" cluster naming for Chinese government-related cyber actors. High-confidence public reporting in this context supports foreign affairs targeting and Chinese state linkage, but does not provide additional corroborated detail on malware families, sub-groups, or a fuller operational playbook for this actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.