IceFog is a Chinese-speaking cyber-espionage threat actor associated with targeted intrusions in Asia and linked in historical reporting to PlugX activity and later malware overlaps involving Quarian. The group is generally treated as distinct from TA428 despite occasional confusion in public reporting and shared tradecraft artifacts across Chinese intrusion sets. IceFog has been connected to infrastructure patterns overlapping with certain PlugX clusters, and later reporting noted a resurgence of activity in 2019 in connection with Quarian-related operations. IceFog has been associated with use of remote access tooling common in Chinese espionage operations, including PlugX and malware ecosystems that overlap with ShadowPad-sharing clusters. Reporting cited in the available facts places IceFog among multiple threat actors known to have used ShadowPad, indicating access to shared tooling rather than exclusive ownership. Historical clustering also linked IceFog-adjacent infrastructure to PlugX groupings alongside other Chinese espionage operations. The actor’s activity is consistent with espionage-motivated targeting of government and diplomatic entities. Available facts support association with Chinese-speaking operations affecting parts of the Middle East and Africa through Quarian and PlugX-linked activity, but do not support a more granular victimology for IceFog specifically beyond those overlaps. Known related names in the broader reporting context include CactusPete, TICK, Winnti Group, and KeyBoy as other actors observed using shared ShadowPad tooling, though these are distinct actors rather than aliases of IceFog.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of several threat actors known to use ShadowPad.
Referenced as having used Quarian in a 2019 resurgence; the 2020 Quarian activity is discussed separately and attributed to CloudComputating, not explicitly to Icefog.
Mentioned only to clarify that it is distinct from TA428 and that shared builder artifacts caused confusion.
Referenced as a known threat group with network-range overlap to PlugX *Http and Starter groups.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.