MISSION2074 is a suspected China-aligned, state-sponsored threat actor associated with repeated cyber-espionage activity across multiple sectors. It has been identified as a highly active operator in observed campaign datasets, appearing both in multi-actor operations and in standalone attributions. Reported activity places it among the most prominent China-linked groups targeting finance, education, and energy and utilities organizations. MISSION2074 has been linked to campaigns against finance-sector entities in numerous countries, with the United States, Japan, India, and South Korea among the leading victim geographies. In that sector, operations have heavily targeted web applications and also included operating system-level intrusion activity. The actor has also been associated with education-sector targeting, where victims spanned a broad international set led by the United States, followed by the United Kingdom, Japan, India, South Korea, and Germany. In education, observed targeting focused on institutional infrastructure such as email, FTP, and SSHD servers, and activity was associated with efforts consistent with access to research data and institutional communications. In the energy and utilities sector, MISSION2074 has been listed among the China-aligned actors dominating observed state-sponsored activity, with victims concentrated in the United States, Japan, India, South Korea, and Australia. Observed tradecraft associated with campaigns involving MISSION2074 includes spear-phishing and supply-chain compromise, alongside exploitation of externally exposed services and web-facing applications. The actor’s behavior is consistent with reconnaissance and initial access operations supporting broader post-compromise objectives. Based on the supplied evidence, MISSION2074 is best characterized as a state-sponsored espionage actor rather than a financially motivated or ransomware-focused group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Most operationally active state-sponsored actor in this finance-sector campaign dataset, appearing across multiple campaigns and geographies.
China-linked state-sponsored espionage activity targeting schools, universities, and research institutions in Q1 2026.
China-aligned state-sponsored activity observed in campaigns affecting energy and utilities victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.