REF2924 is a China-nexus, state-sponsored espionage intrusion set associated with activity publicly tracked as Winnti Group and ChamelGang. It has targeted government and telecommunications organizations in southern and southeastern Asia, including an ASEAN member state's foreign-affairs organization, telecommunications providers in Afghanistan, and likely Mongolian government or nongovernmental entities. Its operations emphasize long-term access, collection, and strategic intelligence objectives rather than monetary gain. REF2924 has used custom backdoors including DOORME, SIESTAGRAPH, SOMNIRECORD, and NAPLISTENER, alongside SHADOWPAD and publicly available or adapted tooling. DOORME is a malicious IIS module that authenticates covert requests and supports in-process shellcode execution. SIESTAGRAPH abuses Microsoft Graph API access to Microsoft 365 mail and cloud storage for command-and-control, command execution, file transfer, network discovery, and screenshot collection. SOMNIRECORD disguises command-and-control and exfiltration as DNS traffic, while NAPLISTENER provides a covert HTTP listener capable of loading supplied .NET assemblies in memory while bypassing normal IIS request logging. The actor has established persistence through services, scheduled tasks, malicious web shells, IIS modules, and temporary privileged domain accounts. It has conducted Active Directory discovery and credential access through directory-database backup and extraction tools, used mailbox collection and export, deployed proxy and tunneling tooling, performed DLL side-loading, and injected payloads into processes. REF2924 has evolved from primarily bespoke malware toward a mixture of custom, open-source, and publicly available tools, retaining environment-specific persistence and collection capabilities. Technical, tactical, victimology, and malware overlaps link the cluster to Winnti Group and ChamelGang activity, though those names are associations rather than established aliases of REF2924.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Intrusion set referenced for using the SIESTAGRAPH backdoor to access Microsoft 365 Mail via the Microsoft Graph API for command-and-control while targeting the Foreign Affairs Office of an ASEAN member.
A previously reported activity cluster involving an attack on a Southeast Asian foreign ministry and notable for abuse of Microsoft Graph API for command and control.
China-nexus espionage intrusion set targeting government diplomatic entities in ASEAN and likely Mongolian government or NGO victims. Associated with multiple malware families and post-exploitation collection activity.
China-nexus espionage intrusion set active in a compromised ASEAN member state's Foreign Affairs Ministry. Its environment contained earlier implants SIESTAGRAPH, NAPLISTENER, SOMNIRECORD, and DOORME, as well as SHADOWPAD and Cobalt Strike; the report also associates it with newly deployed EAGERBEE, RUDEBIRD, and DOWNTOWN tooling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.