Hellsing, also tracked as BRONZE GENEVA, is a Chinese state-sponsored cyber espionage threat actor assessed to operate in alignment with the People's Liberation Army Strategic Support Force. The group has been linked to ShadowPad activity clusters and is part of a broader ecosystem of Chinese operators that have used the modular ShadowPad backdoor since roughly 2019. Hellsing has been associated with use of ShadowPad as a persistent remote access platform capable of host reconnaissance, command execution, file system and registry interaction, deployment of additional modules, and follow-on payload delivery. Observed tradecraft tied to ShadowPad operators includes DLL sideloading and DLL search order hijacking using legitimate executables, in-memory decryption of payloads, persistence through Windows services and autorun mechanisms, and process injection into child processes. ShadowPad-enabled intrusions have also supported hands-on-keyboard post-compromise activity and deployment of additional tooling such as Cobalt Strike in related Chinese operations. The actor is one of several Chinese espionage clusters, alongside groups such as BRONZE BUTLER and BRONZE HUNTLEY, that have been associated with ShadowPad operations beyond its earlier use by BRONZE ATLAS. Available reporting supports classification of Hellsing as an espionage-focused threat actor rather than a financially motivated or ransomware-oriented group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Likely responsible for part of Southern Theater Command-aligned ShadowPad activity targeting organizations in the South China Sea region, with attribution supported by C2 overlap with Nebulae-associated infrastructure.
A Chinese nation-state activity cluster assessed to deploy ShadowPad in operations aligned with the PLASSF.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.