GroundPeony is a China-nexus espionage threat cluster associated with intrusions against government agencies, educational and research institutions, and telecommunications operators in Asia. Reported victim geography includes Taiwan, Hong Kong, South Korea, Nepal, and India. The cluster has been discussed alongside other China-linked groups including Earth Estries (FamousSparrow) and a cluster referred to as Ratel Master, with multiple assessments pointing to cooperation, malware sharing, developer overlap, or shared infrastructure rather than proving they are the same actor. GroundPeony is notably associated with the micDown malware chain and with Mofu Loader, a shellcode loader that has also appeared in operations linked to other Chinese intrusion sets. Its tooling has been delivered through DLL side-loading using legitimate applications, with staged decryption and in-memory execution. Reported technical overlaps with RatelS include use of the same side-loading approach, shared API hashing logic, similar custom XOR-based decoding combined with LZNT1 decompression, and comparable second-stage loader behavior. GroundPeony-linked activity has also been tied to infrastructure overlap with tooling used by Earth Estries/FamousSparrow. The cluster’s observed tradecraft supports a cyber-espionage profile focused on stealthy post-compromise access and malware deployment. GroundPeony has been linked to DLL side-loading, custom loaders, shellcode execution, and persistence-oriented staging. A later intrusion attributed to FamousSparrow reportedly attempted to deploy TernDoor using Mofu Loader previously attributed to GroundPeony, further reinforcing assessments of tooling sharing across related China-aligned espionage ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced because Mofu Loader had previously been attributed to this group; no direct role in the Azerbaijani intrusion is stated.
Cyberespionage activity targeting government, education/research, and telecommunications organizations in Taiwan, Hong Kong, South Korea, Nepal, and India. The content links GroundPeony to micDown and use of Mofu Loader, and notes infrastructure overlap with Earth Estries plus loader overlap with Ratel Master.
Cyber-espionage activity cluster linked in this content to micDown and Mofu Loader, with infrastructure overlap with Earth Estries and code/loader overlap with RatelS/Ratel Master-related tooling.
Mentioned only as another group associated with similar shared tooling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.