ChamelGang, also known as CamoFei, is a suspected China-linked advanced persistent threat group associated with cyberespionage intrusions against government and critical infrastructure organizations. Reported activity has included operations against energy and aviation entities in Russia, government organizations in East Asia, an aviation organization in the Indian subcontinent, and additional government and private-sector targets in the United States, Taiwan, and Japan. The group has also been linked to intrusions affecting the Presidency of Brazil and India’s All India Institute of Medical Sciences. ChamelGang is notable for combining espionage tradecraft with disruptive and financially motivated behavior. Multiple investigations have associated the group with deployment of ransomware and other encryptors, particularly CatB ransomware, in incidents assessed as serving purposes beyond straightforward monetization, including disruption, distraction, misattribution, and removal of forensic evidence. This places the group among China-linked operators observed using ransomware as part of broader intelligence or strategic operations. Observed ChamelGang tradecraft includes use of custom malware such as BeaconLoader, as well as overlaps in malware, techniques, victimology, and strategic targeting with activity associated with Winnti and ShadowPad-linked intrusion clusters. Reporting has tied ChamelGang-related operations to compromises of internet-facing enterprise infrastructure, including Exchange environments, mailbox collection activity, covert persistence, and post-exploitation on victim networks. The group’s operations indicate capability across initial access, persistence, defense evasion, command execution, reconnaissance, and data theft, with occasional use of encryption to disrupt victim response or obscure prior activity. ChamelGang is best characterized as a China-nexus espionage actor that at times blends state-aligned intelligence collection with disruptive and opportunistic ransomware deployment. Known alias: CamoFei.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected Chinese espionage group conducting intrusions against government and critical infrastructure targets and using ransomware/data-encryption tooling, including CatB, in attacks such as those affecting AIIMS and the Presidency of Brazil.
Threat group using ransomware/encryptors across campaigns for mixed objectives: monetization, disruption, and wiping evidence.
Chinese cyberespionage group observed deploying ransomware and encryptors as cover for espionage, disruption, misattribution, evidence removal, and possible financial gain. The content links it to attacks on Brazil’s presidential office and India’s AIIMS healthcare institution.
Activity cluster associated in this content with REF2924 through shared malware, victimology, and strategic targeting, including Exchange server compromises and DOORME deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.