TA428
TA428 is a China-linked cyber-espionage threat actor. The provided reporting links TA428 to operations targeting East Asia and Eurasia, including Mongolian targets and military-industrial, government, and public-sector organizations in Belarus, Russia, Ukraine, and Afghanistan. TA428 is also discussed in relation to activity against Southeast Asian government entities and to malware and infrastructure overlaps involving other Chinese-aligned clusters. Aliases directly mentioned in the content include Vicious Panda. The content also notes possible or alternative naming overlap in some cases with LuckyMouse, Emissary Panda, and APT27, but attribution is described as uncertain in those contexts. TA428 is also discussed as having a notable relationship with the Space Pirates cluster; Positive Technologies reported observing both Space Pirates and TA428 activity on the same infected systems and assessed that they may share tools, infrastructure, and access to compromised systems. Malware and tooling attributed to or previously associated with TA428 in the provided content include PhantomNet (also called SManager and DOWNTOWN), Tmanger, PortDoor, nccTrojan, Logtu, Cotx, DNSep, and use of the Ladon framework. The content also states that PhantomNet was previously attributed to TA428, that Tmanger was attributed to TA428 and used one of the ShadowPad C2 servers, and that five of six backdoors found in one Kaspersky-investigated campaign had been used earlier in attacks attributed by other researchers to APT TA428. Observed tradecraft associated with TA428 in the content includes DLL side-loading, spear-phishing with malicious Microsoft Word documents exploiting CVE-2017-11882, reconnaissance, credential theft, lateral movement using stolen credentials and the Ladon utility, DLL hijacking, process hollowing, and deployment of multiple backdoors for redundant access. In the Kaspersky-described 2022 campaign, the attackers ultimately compromised domain controllers, searched for sensitive files, and exfiltrated data in encrypted password-protected ZIP archives via multi-stage C2 infrastructure, with a second-stage server located in China. The content also places TA428 among confirmed Royal Road users and in a Group-B cluster with Trident, Tick, and Tonto, characterized as targeting East Asia, especially Russia, Korea, and Japan. Additional reporting cited in the content links TA428 to Mongolian targeting through the Able Desktop supply-chain compromise context, where Tmanger delivery was associated with TA428 and infrastructure overlapped with ShadowPad.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇲🇳 Mongolia
Tradecraft
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Observables
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced Chinese threat actor previously attributed with PhantomNet malware that overlaps with tooling seen in Cluster Alpha.
China-linked threat actor referenced for prior attribution of the Ladon post-exploitation framework, which is also used in the described intrusions (as a lateral movement/scanning tool).
Chinese-nexus espionage actor referenced for overlap with Cluster Alpha via PhantomNet/DOWNTOWN and possible linkage through Worok ties.
Cyber-espionage campaign targeting military-industrial complex enterprises and public institutions via spear-phishing with malicious Word documents exploiting CVE-2017-11882, followed by multi-backdoor persistence, lateral movement (including Ladon), domain controller takeover, and staged exfiltration to infrastructure ultimately forwarding data to a server located in China.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.