POISON CARP is a China-aligned cyber-espionage threat actor associated with mobile surveillance operations targeting communities of strategic interest to the Chinese state, especially Tibetans and Uyghurs. The actor is best known for a 2018–2019 campaign against senior members of Tibetan organizations that used tailored WhatsApp social engineering, one-click mobile browser exploitation, and a malicious Google OAuth application to compromise both iOS and Android devices. Victims included personnel linked to the Central Tibetan Administration, the Tibetan Parliament, the Dalai Lama’s office, and Tibetan human rights groups. POISON CARP was identified as the operator behind the first publicly documented use of one-click mobile exploits against Tibetan groups. On iOS, the actor used a browser exploit chain and spyware implant to collect device and application data, including communications and location-related information. On Android, the actor deployed the previously documented MOONSHINE exploit-and-spyware framework, which selected from multiple Chromium-family browser exploits and ultimately installed the modular Scotch implant. Scotch supported plugin-based surveillance functions including collection of SMS messages, contacts, call logs, GPS data, screenshots, camera images, microphone audio, notifications, and shell command execution. The actor also achieved persistence on Android by modifying components within legitimate applications. The group has demonstrated use of public and n-day exploit material, including browser exploits adapted from publicly available research, and has used exploit delivery methods that redirected victims to benign or community-relevant content. Reporting also links POISON CARP to broader MOONSHINE activity targeting Tibetans and Uyghurs through trojanized Android applications and messaging-platform distribution. MOONSHINE infrastructure and management interfaces indicate ongoing development and surveillance-oriented capabilities such as file exfiltration, live audio capture, and screen recording. POISON CARP has been linked in multiple investigations to China’s contractor-based cyber ecosystem. Leaked materials from the Chinese firm i-SOON have been assessed as revealing operational and organizational ties between i-SOON and POISON CARP, alongside other Chinese state-sponsored groups. This places POISON CARP within a broader network of private-sector support to Chinese intelligence and security objectives. Some reporting distinguishes POISON CARP from other China-linked clusters such as Earth Empusa/Evil Eye and Earth Minotaur despite overlaps in targeting, tooling, or infrastructure. The actor’s dominant mission is espionage focused on surveillance, monitoring, and intelligence collection against ethnic minority and diaspora communities viewed as politically sensitive.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
Other exploits include what appears to be lightly modified versions of Chrome exploit code published on the personal GitHub pages of a member of Tencent’s Xuanwu Lab (CVE-2016-1646).
Exploit #2: Appears to be CVE-2016-5198, a bug publicly credited to Tencent’s Keen Security Lab via Trend Micro’s Zero Day Initiative and fixed in Chrome 54.0.2840.87.
Exploit #3: Appears to be CVE-2017-5030, a bug publicly credited to security researcher Brendon Tiszka.
Exploit #4: Appears to include a CVE-2017-5070 exploit published on Qixun Zhao’s Github account of Qihoo 360’s Vulcan Team.
Exploit #6: Appears to be CVE-2018-17463, a bug publicly credited to security researcher Samuel Groß.
3 more CVEs tied to this actor tracked in Mallory.
50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial offensive cyber contractor linked to the Chinese contractor ecosystem, developing and selling offensive cyber tools including spyware, phishing kits, and hardware implants to state customers such as the MSS, PLA, and local Public Security Bureaus.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity.
Conducted a mobile espionage campaign against Tibetan groups via tailored WhatsApp social engineering, delivering iOS and Android browser exploits, spyware, and in at least one case a malicious OAuth phishing application. The campaign overlaps with Uyghur-targeting activity and is likely linked to the same operator or a closely coordinated group behind the Google Project Zero and Volexity-reported campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.