SEQUIN CARP is a China-aligned phishing and surveillance cluster focused primarily on journalists reporting on topics of interest to the Chinese government, especially coverage related to transnational repression and politically sensitive communities. The activity has been observed since at least June 2025 and is assessed to align with Chinese state intelligence priorities; some reporting further assesses with medium confidence that the operators may be commercial contractors acting on behalf of Chinese government customers rather than a core state unit. SEQUIN CARP is distinct from, but closely associated with, the parallel cluster GLITTER CARP. Both clusters have been linked to broader China-aligned espionage and repression activity targeting Uyghur, Tibetan, Taiwanese, and Hong Kong communities, as well as investigative journalists and civil society figures. SEQUIN CARP’s victimology has included international journalists, including reporters connected to investigations into Chinese transnational repression, and at least one defense-focused journalist. The cluster specializes in highly targeted phishing and social-engineering operations. It has used carefully developed personas based on real individuals, impersonation emails, and lures tied to plausible current-affairs narratives to increase credibility. A notable tradecraft element is OAuth consent phishing: instead of only harvesting passwords, SEQUIN CARP has abused legitimate Google OAuth authorization flows to trick victims into granting persistent access to their email accounts. This approach can yield long-lived access through refresh tokens and may survive password changes. Reporting also links the cluster to credential harvesting and theft of third-party access tokens more broadly. Observed tradecraft includes reconnaissance on victim engagement through phishing infrastructure, collection of browser or device fingerprinting data when links are clicked, and reuse of phishing infrastructure and personas across operations. SEQUIN CARP has been noted to share similarities with activity tracked by other vendors as UTA0388 and TAOTH. Overall, the cluster fits a pattern of China-aligned digital transnational repression that blends intelligence collection, surveillance of critics, and compromise of journalist communications.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-affiliated phishing cluster targeting journalists and civil society through impersonation-led phishing, credential harvesting, and OAuth access theft in support of Chinese government intelligence priorities.
Related phishing campaign focused on surveillance and repression of diaspora activists and journalists by stealing email credentials or third-party access tokens.
OAuth consent phishing campaign targeting journalists reporting on China-related issues, especially ICIJ’s China Targets investigation. The group uses co-opted narratives and fabricated or hijacked personas to socially engineer victims into granting persistent third-party access to Gmail accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.