Skip to main content
Mallory
🇨🇳 CN1 malware family

GLITTER CARP

Also known asGLITTER CARP

GLITTER CARP is a China-aligned phishing cluster identified by Citizen Lab and linked to a broader campaign aligned with Chinese government intelligence priorities. Citizen Lab assessed with high confidence that the attacks were carried out at the request of the Chinese government, and with medium confidence that commercial contractors in China’s Military-Civil Fusion ecosystem may have conducted the campaign. The cluster has been active since at least April 2025. GLITTER CARP has targeted Uyghur, Tibetan, Taiwanese, and Hong Kong diaspora activists, as well as investigative journalists and civil society organizations. Reported targets include the International Consortium of Investigative Journalists (ICIJ), journalist Scilla Alecci, the World Uyghur Congress, the Uyghur Rights Advocacy Project, the Uyghur Human Rights Project, Tibetan activists including the Director of TibCERT, Taiwanese media organization Watchout, Hong Kong activist Carmen Lau, and, per Proofpoint reporting, the Taiwanese semiconductor industry. The group conducts broad and persistent phishing and digital impersonation operations focused on obtaining email credentials or third-party access. Observed tradecraft includes impersonation emails mimicking known individuals, journalists, ICIJ-associated identities, and technology company security alerts; credential-harvesting pages; fake login pages; fake security alerts; use of 1x1 tracking pixels to confirm email opens and collect limited device and approximate location telemetry; and reuse of infrastructure, domains, and impersonated personas across campaigns. Citizen Lab tied more than 100 domains to GLITTER CARP over a nine-month period. The cluster also used WhatsApp outreach in at least one case. GLITTER CARP has been linked to overlapping infrastructure and activity previously documented by Proofpoint as UNK_SparkyCarp. Citizen Lab also observed concurrent targeting using an adversary-in-the-middle phishing kit associated with GLITTER CARP and UNK_SparkyCarp. In malware delivery activity associated with this cluster, an email from an Amelia Chavez-themed account delivered a remotely hosted file that would install a custom backdoor if executed; Proofpoint tracks this malware as HealthKick, and Volexity tracks the same or related malware as an early variant of GOVERSHELL. Known aliases and related tracking names mentioned in the reporting include UNK_SparkyCarp; related malware names include HealthKick and GOVERSHELL. GLITTER CARP was reported alongside a separate but related China-affiliated cluster, SEQUIN CARP, as part of a broader pattern blending state espionage with digital transnational repression.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Media & Entertainment
  • Independent Media
  • Semiconductors & Semiconductor Equipment

Where they target

Geographies tied to known operations.

  • 🇨🇦 Canada
  • 🇹🇼 Taiwan
  • 🇬🇧 United Kingdom

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics14 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1592
Gather Victim Host Information
T1598
Phishing for Information
TA0001
Initial Access
1 technique
T1566×4
Phishing
T1566.001
Spearphishing Attachment
T1566.002×3
Spearphishing Link
TA0002
Execution
1 technique
T1204
User Execution
T1204.002
Malicious File
TA0005
Stealth
2 techniques
T1027
Obfuscated Files or Information
T1036×2
Masquerading
TA0006
Credential Access
3 techniques
T1056×3
Input Capture
T1528
Steal Application Access Token
T1557×2
Adversary-in-the-Middle
TA0009
Collection
2 techniques
T1056×3
Input Capture
T1557×2
Adversary-in-the-Middle
IOCS

Observables

121 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping11

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables121

Domains, IPs, and hashes tied to this actor, refreshed continuously.