Macha Grass is a South Asian advanced persistent threat activity cluster observed using COVID-19-themed social engineering in 2020 against Chinese targets. It has been identified in reporting alongside other regional espionage groups active during the first half of 2020. The actor used pandemic-related lures as part of spearphishing operations directed primarily at strategic organizations and personnel. Available reporting directly associates Macha Grass with pandemic-themed APT activity targeting Chinese-speaking organizations during the early phase of the COVID-19 outbreak. Such activity fits a broader espionage pattern in which government, military, medical, and other strategic entities were targeted through topical lures. Publicly available facts in this context do not provide sufficient high-confidence detail on the group’s malware families, infrastructure, organizational structure, aliases beyond the Chinese name, or a definitive state sponsor attribution. Based on the supported facts, Macha Grass should be characterized as an espionage-oriented threat actor conducting initial-access operations through themed phishing and social engineering against strategic targets in China during 2020.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
South Asian APT group that used COVID-19-themed lure documents early in the pandemic to target Chinese entities.
Referenced as one of several South Asia-related groups previously tracked by the researchers; not part of the specific campaign analysis here.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.