TeamDonut is a security research team associated with analysis of phishing operations targeting Japan. The group is known for research into the CoGUI phishing campaign and its linkage to the China-based phishing-as-a-service platform FishingMaster, also referred to by its Chinese name 垂钓大师. Publicly identified members include Shadow Liu, Lime Chen, and Albert Song. Their work has focused on uncovering the infrastructure, operational patterns, and ecosystem dependencies behind large-scale phishing activity aimed at Japanese brands and services. TeamDonut’s reported research attributes CoGUI operationally to a China-based PhaaS ecosystem and documents targeting of Japanese organizations and brands in the financial, transportation, and government service sectors. The activity they analyzed reflects industrialized phishing tradecraft, including use of phishing kits, administrative panels, infrastructure concealment, encrypted communications, and detection-evasion improvements. The operators behind the platform were reported to have temporarily suspended operations after public exposure and later resumed under rebranded names including NX and FA. TeamDonut is not described as a threat actor conducting intrusions or monetized attacks itself, but rather as a defender-side research collective recognized for exposing a major phishing ecosystem affecting Japan.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the presenting group for research on the CoGUI phishing kit, described as a major China-linked phishing-as-a-service operation targeting Japan. No additional operational details are provided in this text.
Security research team presenting analysis of the CoGUI phishing campaign and the FishingMaster PhaaS platform; not described as the operator of the campaign in this text.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.