NetTraveler, also known as Travnet, is a long-running cyberespionage threat actor and associated malware campaign assessed to be linked to Chinese-speaking operators. Activity has been observed since at least the mid-2000s, with the largest volume of known malware samples created between 2010 and 2013. The operation has targeted high-profile victims in more than 40 countries, including political activists, research centers, government institutions, embassies, military contractors, and private companies. NetTraveler primarily gains initial access through spear-phishing emails carrying malicious Microsoft Office documents that exploit known Office vulnerabilities such as CVE-2012-0158 and CVE-2010-3333. The malware is designed chiefly for document theft and basic surveillance. It focuses on collecting common office and document formats and has also targeted engineering and design-related file types in some configurations, indicating interest in technical and industrial information. The malware supports credential-adjacent surveillance through keylogging with application-context capture, including reporting window names alongside keystroke data. Reporting has also associated NetTraveler with steganography use in some operations. Related malware families used alongside the campaign include Saker, also known as Xbox, and PCRat, also known as Zegost. Victimology and infrastructure overlaps have also been noted in broader reporting involving other China-linked intrusion clusters. NetTraveler is notable for achieving extensive espionage outcomes without reliance on zero-day exploits or especially advanced stealth components such as rootkits. Known targeting themes have included space exploration, nanotechnology, energy production, nuclear power, lasers, medicine, and communications, reflecting a strong intelligence-collection orientation against governmental, diplomatic, defense, scientific, and strategic industrial entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The primary attack method consists of spear-phishing emails carrying malicious documents that exploit two remote code execution vulnerabilities that affect Microsoft Office, namely CVE-2012-0158 and CVE-2010-3333, in order to install the malware.
The primary attack method consists of spear-phishing emails carrying malicious documents that exploit two remote code execution vulnerabilities that affect Microsoft Office, namely CVE-2012-0158 and CVE-2010-3333, in order to install the malware.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/activity cluster explicitly listed as using steganography in attacks.
Referenced due to overlapping domain registration artifacts with infrastructure later connected indirectly to ShadowPad activity; targeted CIS and Europe.
Cyberespionage campaign compromising high-profile victims across more than 40 countries over eight years, focused on stealing documents and conducting basic surveillance against activists, research centers, government institutions, embassies, military contractors, and private companies.
Keylogging operations augmented with window-title reporting to provide application context.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.