1937CN is a Chinese patriotic hacktivist group active from roughly 2012 to 2016 and known for cyber operations aligned with PRC geopolitical interests, especially disputes in the South China Sea. The group is widely associated with anti-Vietnam and anti-Philippines activity and has been described as pro-PRC and hawkish in its messaging. Public reporting has linked 1937CN to large-scale website defacements, disruptive attacks, data exposure incidents, and intrusions timed to regional political flashpoints. 1937CN first became prominent through campaigns against Vietnamese targets. In 2014, amid tensions over maritime disputes, the group claimed retaliatory attacks that defaced hundreds of Vietnamese commercial, educational, and government websites. Later that year, activity attributed to 1937CN and Sky-Eye Team reportedly affected hundreds more Vietnamese sites, with evidence that attackers implanted malicious code rather than conducting simple defacements alone. The group also targeted Philippine websites during periods of heightened South China Sea tension. 1937CN is most widely known for the July 2016 attacks on Vietnam’s aviation sector. In that operation, attackers disrupted airport information and public-address systems at major Vietnamese airports, defaced Vietnam Airlines infrastructure, and exposed personal data from the airline’s frequent-flyer program. The incident caused operational disruption and manual processing of check-ins while broadcasting pro-China and anti-Vietnam messaging. Reporting also notes overlap between malware and infrastructure used in broader espionage activity against Vietnamese organizations. The group has been linked in some reporting to campaigns using politically themed lure documents exploiting CVE-2012-0158, DLL sideloading or hijacking with signed binaries, in-memory downloader execution, persistence via autorun mechanisms, host profiling, and deployment of the NewCore remote access trojan. NewCore supported file management, command execution, screen monitoring, and system control, indicating post-compromise espionage capability beyond overt defacement. Commercial threat intelligence reporting has also assessed 1937CN as effectively interchangeable with, or closely overlapping, the PRC-aligned espionage actor Goblin Panda, though such linkage is not uniformly established in all public reporting. Overall, 1937CN represents the convergence of patriotic hacktivism and more capable intrusion tradecraft in support of Chinese political objectives. Its operations have combined propaganda, disruption, credentialed or unauthorized access to victim systems, persistence, malware deployment, and data theft, with Vietnam as the clearest recurring target set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a named threat actor in source data associated with the win.raccoon entry.
Listed as a named actor associated with the win.metamorfo entry in the provided content.
Listed as a newly associated actor for the win.kpot_stealer malware family.
Chinese hacktivist group conducting politically motivated compromises and defacements against Vietnam and the Philippines, including airport system intrusions and data exposure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.