Luckycat
LuckyCat is malware/campaign infrastructure identified by Trend Micro in March 2012 as part of a Chinese cyber campaign. According to the provided content, LuckyCat targeted U.S.-based activists and organizations, Indian and Japanese military research entities, and Tibetan activists. The content also states that infrastructure associated with later Tibetan-targeting malware campaigns overlapped with LuckyCat infrastructure, including historic phishing activity using the sender account tseringkanyaq@yahoo[.]com and later links between a LuckyCat Android RAT variant and ExileRAT-related operations. Based on the supplied material, LuckyCat is associated with Chinese-linked targeting of Tibetan interests and other geopolitical targets, but specific technical details on its capabilities, infection vector, or standalone indicators of compromise are not provided here beyond the noted infrastructure sharing and campaign targeting.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
1 technique
Initial Access
Execution
2 techniques
Execution
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Collection
1 technique
Collection
Recent activity
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named China-linked cyber-espionage campaign (as described) targeting activists and military research; the content does not provide a specific malware family name used within the campaign.
A named China-linked cyber-espionage campaign (as described) targeting activists and military research entities; the specific malware family used is not detailed in the provided content.
A China-attributed cyber-espionage campaign targeting activists and military-research-related entities, including Tibetan activist communities and Indian/Japanese military research.
A named China-linked cyber-espionage campaign (as described) targeting activists and military research; the specific malware family/tooling used is not detailed in the provided content.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.