TeleBoyi is a China-nexus advanced persistent threat group active since at least 2014 and primarily associated with cyber-espionage against critical infrastructure organizations worldwide, with a particular focus on the Asia-Pacific region and the telecommunications sector. Reported targeting has also included energy, information technology, manufacturing, healthcare, government, and financial services entities. Its operations are consistent with intelligence collection, technology theft, and preparation for future strategic access. TeleBoyi uses multiple initial-access pathways, including trojanized or fake applications, malicious documents containing macros or HTA content, and exploitation of public-facing applications such as Microsoft Exchange, Apache Struts2 S2-045, and Java deserialization vulnerabilities. Post-compromise activity has included deployment of webshells, custom loaders, and a diverse malware arsenal. Malware and tooling associated with the group include PlugX, Winnti, ShadowPad, DeedRAT, TripleZero, LibreCoin, DoubleShell, FakeWorker, Cobalt Strike, Sliver, and AsyncRAT. DoubleShell and FakeWorker have been highlighted as previously undisclosed malware families linked to the actor. TeleBoyi demonstrates strong malware development and operational tradecraft. Reported techniques include self-extracting archive packaging, custom loaders protected with commercial packers, encrypted payload staging, reflective DLL injection, and DLL sideloading. LibreCoin has been described as supporting remote shell access, file operations, proxying, screenshots, and keylogging. DoubleShell has been described as a multi-stage backdoor supporting command execution, file management, screenshots, and dead-drop resolver-based command-and-control updates. FakeWorker has been described as a Linux backdoor supporting file transfer and pseudo-terminal command execution. The group has also used infrastructure patterns such as domains impersonating organizations relevant to victim sectors and compromised websites for command and control. TeleBoyi has been linked to overlap with Operation Harvest and assessed to have connections, collaboration, or malware-sharing relationships with other Chinese intrusion clusters including APT41, Earth Berberoka, FamousSparrow, GroundPeony, and SLIME40. Some reporting notes weak and inconclusive links between TeleBoyi and later ShadowPad activity associated with ransomware deployment, but attribution of that activity to TeleBoyi itself remains low confidence and should not be treated as established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possible but weak attribution candidate for the observed Shadowpad/PlugX-linked activity based on code overlap and historical infrastructure overlap.
China-nexus espionage group active since 2014 targeting critical infrastructure worldwide, especially in APAC, with a strong focus on telecommunications as well as energy, IT, manufacturing, healthcare, nuclear, government, and financial sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.