Moshen Dragon is a suspected Chinese-linked threat actor name that appears in reporting as part of broader clusters of activity involving Chinese-origin operations. Publicly available information in this context does not provide a distinct, well-corroborated operational profile for Moshen Dragon as a standalone actor. It is referenced alongside other Chinese and Iranian threat activity in a heavily compromised environment, but no unique malware set, intrusion chain, victimology, or attribution details are established here with high confidence. Because the available evidence is limited to contextual mention rather than a dedicated attribution case, Moshen Dragon should be treated as an alias or reporting label with insufficient confirmed detail for a fuller characterization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of several known threat actors cohabiting the same victim environment; no specific activity beyond presence in the compromised environment is described in this content.
Mentioned only as another report tying similar malware artifacts to a named cluster; not linked by the authors to the focal campaign with confidence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.