haiau009 is a threat-actor handle and Packagist vendor namespace associated with a software-supply-chain campaign involving trojanized Composer website themes. The malicious themes were deployed by Vietnamese movie and comic streaming websites and injected browser-side JavaScript into affected sites. The loaders fingerprinted device characteristics, iOS versions, and referral sources; they avoided desktop browsers, automated scanners, and direct visitors to reduce exposure. Some mobile visitors were redirected to gambling-related content, while selected iPhone users were served an exploit chain targeting the patched WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 on older iOS releases. The resulting iOS spyware collected Keychain data, Wi-Fi credentials, messages, contacts, photographs, browser cookies, call history, location records, and account data; encrypted the collected information; and exfiltrated it through rotating command-and-control infrastructure. A later observed variant added cryptocurrency-wallet theft by searching Keychain data for seed phrases and mnemonic recovery material. haiau009 is associated with the broader campaign alongside the vsmov, vsphim, chilltvcms, and ophimcms Packagist namespaces.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the malicious Composer-theme supply-chain campaign targeting streaming-site operators and their visitors, including selected iPhone users targeted with WebKit exploits and spyware capable of stealing wallet recovery data.
Associated with the Composer-theme supply-chain operation that serves malicious browser-side loaders to streaming-site visitors and selectively deploys iPhone spyware with wallet-theft capability.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.