TA413, also tracked as White Dev 9 and LuckyCat, is a China-based, Chinese state-aligned advanced persistent threat group focused on cyberespionage and surveillance of civil dissidents. Its principal targets are Tibetan organizations, dissidents, diaspora communities, and entities associated with the Tibetan government-in-exile. It has also targeted European diplomatic and legislative bodies, nonprofit policy research organizations, and international organizations involved in economic affairs. The group was publicly documented under the TA413 designation in 2020. TA413 conducts spearphishing and watering-hole operations, using Tibetan political and community themes, impersonation of trusted organizations, and malicious Office documents. It employs the Royal Road RTF weaponizer to exploit Microsoft Equation Editor vulnerabilities, including CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802. In 2022, it exploited the Sophos Firewall authentication-bypass and remote-code-execution vulnerability CVE-2022-1040 before public disclosure and rapidly adopted the Follina vulnerability, CVE-2022-30190. Its tooling includes Sepulcher, ExileRAT, LOWZERO, the FriarFox Firefox extension, and the ScanBox reconnaissance framework. Sepulcher supports host reconnaissance, file manipulation, reverse-shell access, and scheduled-task persistence. FriarFox modifies an open-source Gmail notification extension to access and manipulate victims' Gmail accounts and collect browser data; delivery uses fake software-update pages tailored to Firefox users. ScanBox supports browser reconnaissance, keylogging, and data collection. LOWZERO profiles compromised systems, supports additional executable modules and network proxying, and uses process injection, layered payload obfuscation, and a custom TLS-like command-and-control protocol. TA413 has repeatedly reused phishing identities and infrastructure across campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The downloaded HTML file uses the ms-msdt MSProtocol URI scheme to trigger the Follina exploit and ultimately execute a Base64-encoded PowerShell command to download a follow-on payload.
Over the first half of 2022, we have observed TA413 exploit a now-patched zero-day vulnerability targeting the Sophos Firewall product (CVE-2022-1040).
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed to the 2019 Holy Water watering-hole campaign, which compromised religious and charitable websites targeting Asian religious minorities to deliver the ScanBox framework and collect victim-system and browsing data.
Historically reported targeting of Tibetan organisations; referenced here due to overlaps in domain registration patterns and spoofing of Tibetan-themed infrastructure.
Likely Chinese state-sponsored cyber-espionage group persistently targeting Tibetan organizations, individuals, and government-in-exile entities. Its 2022 campaigns combined firewall zero-day exploitation, rapid adoption of Follina, Royal Road malicious documents, and the LOWZERO backdoor. Historical activity also targeted European diplomatic and legislative bodies and nonprofit policy research organizations. Network observations linked its infrastructure to government organizations in Nepal and an Indian ISP. Shared malware and infrastructure suggest operational overlap with Tropic Trooper, but the report does not establish that they are the same group.
Named as one of several China-based threat actors observed using the ScanBox framework.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.