Glacier is described as China’s first domestically created Remote Access Trojan (RAT), developed by Huang Xin during the 1999 China–Taiwan tensions while he was associated with the Green Army. The malware is presented as an early indigenous Chinese RAT whose popularity helped lower the barrier to entry for aspiring operators in China’s early “red hacker” ecosystem. The content places Glacier in the broader evolution of Chinese hacking communities from defacements and DDoS activity toward development of indigenous offensive tooling, alongside later tools such as X-Scan and HTRAN. It is associated in the source material with the formative period of Chinese patriotic hacking and the emergence of domestic technical capability that later fed into China’s wider cyber ecosystem. The provided content does not include specific technical details on Glacier’s command-and-control protocol, persistence, propagation, targeted operating systems, sectors, or concrete indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
…developed “Glacier,” China’s first domestically created Remote Access Trojan (RAT). Glacier’s popularity helped lower the entry barrier…
1 distinct technique documented for this family, organized by ATT&CK tactic.
“developed ‘Glacier,’ China’s first domestically created Remote Access Trojan (RAT)… catalyzed a wave of indigenous RATs… ‘Graybird,’ ‘Shady RAT,’ ‘Net Thief,’ and ‘YAI.’”; “In 2008, a new remote access Trojan named PlugX…” | “...developed ‘Glacier,’ China’s first domestically created Remote Access Trojan (RAT). Glacier’s popularity helped lower the entry barrier… catalyzed a wave of indigenous RATs…” / “Foreign tools—such as … Black Orifice remote access trojan…”
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Early China-developed RAT with a user-friendly interface that enabled remote control/intrusion and helped catalyze follow-on indigenous RAT development.
Early Chinese-developed remote access trojan used to enable remote control of compromised systems; described as lowering the entry barrier for Chinese hackers and catalyzing follow-on indigenous RAT development.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.