Blastoize is a threat actor name associated with the public posting and redistribution of a partial archive of corporate documents from Knownsec, a Chinese cybersecurity company reported to have ties to Chinese government and military entities. Available reporting does not support attributing the original Knownsec compromise to Blastoize; instead, Blastoize is linked to republishing material from the broader Knownsec leak that first surfaced in late 2025. The redistributed material was described as containing portions of a much larger exposure involving offensive cyber tooling, surveillance-related documentation, target lists, and records of alleged data theft operations. Reported contents included documentation and source code for remote access tooling across multiple operating systems, Android malware used to collect chat data, hardware-based attack concepts for covert data collection, and infrastructure-mapping activity using vulnerability-scanning capabilities. The leaked records also allegedly documented targeting of foreign government agencies, telecommunications providers, and critical infrastructure operators, as well as collaboration between Knownsec and Chinese state entities. Based on currently available facts, Blastoize is best characterized as a leak or disclosure persona rather than a clearly established intrusion set or state-directed operational cluster. There is insufficient high-confidence information to assess Blastoize's origin, organizational structure, or broader campaign history beyond the reposting of leaked Knownsec materials. The dominant observable behavior directly tied to the name is exfiltration-related disclosure or publication of stolen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.