ta413
TA413 is a China-aligned advanced persistent threat group associated with espionage and surveillance activity, particularly against the Tibetan community and Tibetan diaspora. Reported aliases include White Dev 9 and LuckyCat. The actor has conducted sustained phishing and malware campaigns targeting Tibetan organizations, Tibetan dissidents, individuals associated with the Tibetan leadership in exile, and the broader Tibetan community. Reporting also describes TA413 exploiting Follina (CVE-2022-30190) in phishing campaigns targeting the Tibetan diaspora, with some campaigns also affecting officials in Europe and the United States. TA413 has been linked to delivery and use of multiple malware families and tools including ExileRAT, Sepulcher, FriarFox, ScanBox, and BADBAZAAR-related infrastructure overlaps. Proofpoint attributed 2020 Sepulcher campaigns to TA413, including a WHO COVID-19-themed campaign targeting European diplomatic, legislative, policy, and economic organizations, and a later Tibetan-themed campaign targeting Tibetan dissidents. Sepulcher is described as a basic RAT with host reconnaissance, reverse shell, file read/write capability, scheduled-task persistence, and encrypted configuration stored in the Windows registry. In early 2021, TA413 delivered the malicious Firefox extension FriarFox via phishing emails impersonating Tibetan organizations including the Tibetan Women’s Association and the Bureau of His Holiness the Dalai Lama. FriarFox, a modified version of the open-source Gmail Notifier extension, enabled access to Gmail accounts and browser data and could forward, delete, and send emails from compromised accounts. The campaign used fake Adobe Flash update pages and served payloads selectively to Firefox users, in some cases when logged into Gmail. FriarFox was also observed retrieving the ScanBox reconnaissance framework. TA413 tradecraft described in the reporting includes phishing, watering hole activity, use of fake update pages, impersonation of legitimate organizations, Royal Road RTF weaponization, exploitation of a Microsoft Equation Editor vulnerability, and use of ScanBox for reconnaissance and keylogging. The reporting also notes overlap between keyboard-walk WHOIS values in BADBAZAAR-linked domains and historically reported TA413 targeting of Tibetan organizations. Across the cited reporting, TA413 is consistently described as focused on espionage and civil dissident surveillance aligned with Chinese state interests.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Non-Governmental Organizations
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historically reported targeting of Tibetan organisations; referenced here due to overlaps in domain registration patterns and spoofing of Tibetan-themed infrastructure.
Named as one of several China-based threat actors observed using the ScanBox framework.
Exploited the Follina (CVE-2022-30190) MSDT RCE zero-day in phishing/lure-based attacks targeting the Tibetan diaspora.
Actively exploiting the Follina vulnerability in phishing campaigns, with ongoing hacking operations against the Tibetan community and victims including officials in Europe and the United States.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.