EvilOctal, also known as the EvilOctal Security Team, was a Chinese red-hacker community active during the late-1990s to 2000s era of China’s early hacker ecosystem. It was one of several prominent patriotic hacker groups that combined a public-facing forum community with a much smaller core of active members. Reported membership figures for EvilOctal reached 9,562 registered users in 2006, but available evidence indicates that its operationally relevant core was far smaller, with 31 core members listed by 2010. Like comparable Chinese red-hacker groups of the period, EvilOctal appears to have functioned as a community organization as much as an operational team, with core members handling both technical work and supporting roles such as administration, coordination, and site management. EvilOctal should be understood in the context of China’s broader red-hacker movement, in which large public membership numbers often reflected low-barrier forum registration rather than a vetted cadre of capable operators. The most technically proficient participants typically represented only a small fraction of the broader user base, while many peripheral members were hobbyists or amateurs. High-confidence reporting supports EvilOctal’s existence as part of this formative Chinese hacker milieu, but does not directly attribute specific intrusion campaigns, malware families, victim sectors, or named operations to the group. As a result, detailed operational targeting, capability, and motivation assessments for EvilOctal remain currently not available at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.