Poison Vine, also tracked as APT-C-01, is an unattributed cyber espionage group alleged by Chinese authorities to be associated with Taiwan’s Information, Communications and Electronic Force Command. Its reported targeting profile is consistent with intelligence collection against Chinese entities, particularly government, scientific, military, and maritime organizations. Government and scientific institutions are the most consistently cited victim classes, with additional reporting indicating long-duration collection against Chinese strategic sectors. The group has been described as using phishing for initial access, followed by malware deployment and data exfiltration. Reported activity overlaps with other alleged Taiwan-linked clusters in its use of phishing-led intrusions against public-sector and research targets. Claimed tradecraft includes reliance on known vulnerabilities, public or commercial tooling, and comparatively weak anti-tracing practices, although those capability assessments derive from adversarial public attribution and should be treated cautiously. No high-confidence public evidence in the supplied material supports ransomware or destructive operations by this actor. Known aliases include APT-C-01 and Poison Vine. "Poison Ivy Group" and "GreenSpot" are also cited as associated names in reporting. The actor is best characterized as an espionage-focused cluster targeting Chinese state, research, and strategic organizations for intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
122 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unattributed espionage group conducting long-duration intelligence collection against Chinese government, military, maritime, scientific, and academic organizations using cloned websites and malware delivery.
One of five Taiwan-attributed APT groups (per CVERC claim) alleged to conduct cyber espionage against mainland China entities; also claimed to have 'close ties' with U.S. Cyber Command and to focus on 'hunt forward' operations.
Targeting government and scientific organizations, allegedly operated by Taiwan's Information, Communications and Electronic Force Command with U.S. assistance.
APT-C-01 is accused of conducting phishing attacks against government and scientific targets, installing malware, and exfiltrating data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.