ChainedShark is an advanced persistent threat group identified in 2025 and assessed to have been active since May 2024. The group is characterized by strategically coherent, technically sophisticated operations focused on China’s scientific research sector. Its primary victims are professionals at Chinese universities and research institutions, especially individuals working on international relations, marine technology, and related disciplines. The activity indicates an intelligence-collection mission centered on obtaining sensitive diplomatic and marine-technology information. ChainedShark relies heavily on tailored social engineering, using fluent Chinese-language lures framed as legitimate academic and professional exchanges such as conference invitations and calls for papers. The group has shown a mature and repeatable targeting process, including reuse of themes, phrasing, and victim selection across multiple campaigns. Its tradecraft includes exploitation of known vulnerabilities, delivery of custom malware, and strong concealment measures. Reported tooling includes the custom trojan LinkedShell, described as highly customized and equipped with advanced anti-forensic features. Later operations shifted toward use of the GrimResource vulnerability to streamline intrusion workflows. ChainedShark has also been associated with executable reconstruction techniques that transform PE components into shellcode for concealment, reflecting an emphasis on stealth and defense evasion. Overall, the group demonstrates sustained weapon development, mature infrastructure, and attack chains consistent with a state-sponsored espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as an APT group using executable file reconstruction: deconstructing and reassembling Windows PE files into large, fragmented shellcode (~3MB) to deeply conceal payloads, suggesting automation and weaponization of the technique.
Espionage-focused activity targeting Chinese universities and research institutions (notably international relations and marine technology) using high-quality Chinese-language social engineering lures (conference invitations/call-for-papers), custom malware, and exploitation of public (N-day) vulnerabilities to steal sensitive data and intelligence.
Newly disclosed espionage-focused activity cluster targeting China’s scientific research sector, particularly professionals at Chinese universities and research institutions working on international relations and marine technology.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.