CeranaKeeper is a China-aligned intrusion set engaged in cyberespionage, with activity publicly linked to campaigns targeting Southeast Asia, particularly Thailand, and broader political and governmental entities in Asia and Europe. The cluster has been associated with malware and tooling including TONESHELL, PUBLOAD, WavyExfiller, and MQsTTang. MQsTTang, later reassigned from Mustang Panda to CeranaKeeper, is a custom backdoor that uses MQTT over a legitimate public broker for command and control, executes arbitrary commands, returns command output, incorporates anti-analysis checks, and establishes persistence on compromised Windows systems. Reported delivery tradecraft includes spearphishing-style lures using diplomacy- and passport-themed decoys, indicating an emphasis on government and foreign affairs targets. CeranaKeeper has operational and tooling overlap with the broader ecosystem of PRC-linked espionage activity, especially clusters historically associated with Mustang Panda, also tracked as Stately Taurus, TA416, BRONZE PRESIDENT, Hive0154, and Earth Preta. However, CeranaKeeper has been separated as its own intrusion set based on refined attribution and TTP distinctions. Known targeting includes Thai officials and likely governmental or political organizations, with telemetry also indicating victims in Bulgaria and Australia and targeting of a governmental institution in Taiwan. The actor’s observed behavior supports an espionage mission focused on long-term access, covert command execution, persistence, and data collection from government-related victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeting-focused activity (explicitly Thailand in the referenced title) associated with tooling including PUBLOAD/TONESHELL and data exfiltration components.
China-aligned intrusion set mentioned as an overlapping cluster related to ToneShell-style activity.
Per the update, CeranaKeeper (not Mustang Panda) is now assessed responsible for MQsTTang activity; the described TTPs (MQTT C2 via public broker, spearphishing-delivered RAR payloads, GitHub user YanNaingOo0072022 linkage, and persistence/anti-analysis behaviors) are stated to align more closely with CeranaKeeper.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.