Hong Kong Blondes was a dissident hacktivist group referenced in connection with the Cult of the Dead Cow (cDc). The available content states that cDc members teamed up with the Hong Kong Blondes to hack Chinese government agencies and companies with poor human rights records in China. A cited press release says the purpose of the partnership was to help the Hong Kong Blondes develop a hacking capability, and that the groups later ended their cooperation after that goal had been achieved, partly out of concern for potential security breaches. The same release states that the Hong Kong Blondes intended to continue their work after the split. Based on the provided content, the group is associated with pro-democracy and anti-censorship activism focused on China. No additional aliases or sub-groups are directly supported beyond the name Hong Kong Blondes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dissident hacktivist group collaborating with cDc to target Chinese government agencies and companies associated with poor human rights practices.
Named hacking group that had worked with Cult of the Dead Cow to develop a 'lean mean hacking machine' and intended to continue its operations afterward.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.