NanHaiShu is a malware family and associated intrusion activity noted for using simple obfuscation and living-off-the-land execution to stage and run malicious components on Windows systems. Reported tradecraft includes encoding files with Base64 and using mshta.exe to load and execute its program and related files, indicating reliance on native Windows utilities for execution and defense evasion. High-confidence public information in this context is limited, and attribution to a specific nation-state or broader threat cluster is not established here.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses Base64-encoded files.
Uses mshta.exe to load its program and associated files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.