Naikon, also tracked as Growing Taurus, is a Chinese state-linked espionage threat actor known for long-term intrusions against government targets, particularly in Southeast Asia. The group has been associated with sustained access operations focused on intelligence collection, resilient persistence, and post-compromise maneuvering rather than disruptive or ransomware-driven outcomes. Naikon has been linked to operations exploiting Microsoft Exchange Server vulnerabilities for initial access, followed by deployment of web shells such as China Chopper to enable interactive command execution and footholds on exposed servers. Observed tradecraft includes extensive reconnaissance, creation of attacker-controlled administrative accounts, internal network scanning, credential theft, attempted Kerberos account enumeration and brute forcing, LSASS dumping, extraction of stored credentials, and NTLM hash collection. The actor has also used remote administration and tunneling tools, including VPN and proxy utilities, to preserve access and move within victim environments. Malware and tooling associated with Naikon-linked activity include custom and commodity backdoors, remote access trojans, tunneling tools, and credential access utilities. Reported tooling in attributed operations has included undocumented .NET backdoors, Cobalt Strike, Quasar RAT, customized HDoor, Gh0st RAT-derived malware, and a Winnti-family variant, alongside utilities such as Mimikatz, LaZagne, Kerbrute, HTran, PuTTY/Plink, SoftEther VPN, and AnyDesk. The group’s operational pattern emphasizes layered access, redundant persistence, defense evasion through renamed binaries and legitimate administration tools, and lateral movement toward high-value systems such as web servers and domain controllers. Naikon is widely assessed as operating in support of Chinese state interests. Its targeting and tradecraft are consistent with strategic espionage against public-sector entities in Asia, especially government organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.