蔓灵花 is a South Asian advanced persistent threat cluster referenced in connection with espionage activity targeting Chinese organizations. It has been observed using COVID-19-themed lures against domestic Chinese targets during the first half of 2020. Reporting also associates the group with a custom malware sample referred to as Winlogs.exe and with phishing tradecraft similar to that used in other South Asian espionage operations. Infrastructure overlap has been noted between assets linked to 蔓灵花 and those used in the Tibbar campaign attributed to Confucius, indicating shared or overlapping network resources, although this overlap is not sufficient to merge the two clusters. Available information supports characterization of 蔓灵花 as an espionage-oriented actor, but public detail in this context is limited regarding its full malware arsenal, victimology breadth, or organizational structure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
South Asian APT group observed using COVID-19-themed attacks against Chinese targets.
Another South Asia-linked APT cluster referenced because of overlapping infrastructure and similar phishing tradecraft with Confucius/Tibber, but the report does not attribute the campaign directly to it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.