REF3864 is an unattributed intrusion set targeting Chinese-speaking users with trojanized installers impersonating legitimate software, including communications and browser applications. Active since at least December 2023, it uses the SADBRIDGE Windows loader to deploy GOSAR, a Go-based reimplementation of the QUASAR remote-access trojan that supports Windows and Linux. Chinese-language logging, security-product checks, and firewall-rule text indicate that both targeting and operators are likely Chinese-speaking, but no state, criminal group, or country attribution has been established. REF3864 commonly delivers malicious MSI installers in archive files. SADBRIDGE executes through DLL side-loading, decrypts staged payloads, and uses APC injection, PoolParty thread-pool injection, and token manipulation to inject processes. It can bypass UAC through COM abuse, create SYSTEM-level scheduled tasks, and establish persistence through an auto-start Windows service. It impairs host defenses by patching AMSI and ETW functions and uses extended sleep intervals to resist sandbox analysis. GOSAR provides remote command execution, host and security-product discovery, process and service control, file operations, screenshot capture, keylogging, clipboard monitoring, plugin loading, and hidden VNC and RDP-related remote-access functions. It collects system, network, clipboard, antivirus, and digital-wallet-related information and communicates using a protocol compatible with QUASAR over TCP protected by TLS.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate intrusion set mentioned for comparison, associated with malicious installers targeting Chinese-speaking regions and linked to SADBRIDGE and GOSAR activity.
An intrusion set conducting organized malware campaigns against Chinese-speaking victims using trojanized installers masquerading as legitimate software such as Telegram and Opera GX. The activity uses the SADBRIDGE loader to deploy the Golang-based QUASAR variant GOSAR across Windows, with broader multi-platform malware delivery also noted for Linux and Android.
Conducting cross-platform intrusion campaigns against Chinese-speaking victims using trojanized installers impersonating Telegram and Opera. The group uses SADBRIDGE for DLL side-loading, process injection, privilege escalation, persistence, and defense evasion, ultimately deploying the Go-based GOSAR remote-access trojan.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.