Phoenix Overseas Resources is a Chinese-language data broker presence active on Telegram since late 2024 that advertises large volumes of purportedly stolen data, including alleged records from Gulf-based financial and investment services. Available reporting assesses it as part of a broader ecosystem of Chinese-language sellers distributing low-credibility "lead data" rather than reliably demonstrating genuine network intrusions or fresh breaches. Its advertised samples have been found to contain recombined and inconsistent personal data drawn from older public leaks, with mismatched identities across fields, indicating repackaging or fabrication rather than direct compromise of the claimed victims. The administrator was observed participating in Telegram communities focused on data collection, exchange, and scraping before the channel’s emergence. Based on currently available facts, Phoenix Overseas Resources is best characterized as a data brokerage or fraud-oriented actor involved in marketing and possible resale of recycled personal data. High-confidence evidence does not support attribution to a state sponsor, nor does it substantiate capabilities such as initial access, privilege escalation, or ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.