Earth Minotaur is a China-aligned cyber-espionage threat cluster associated with Android and Windows surveillance tooling and adversary-in-the-middle delivery operations. The actor is best known for using the MOONSHINE exploit kit to compromise Android devices and deploy the DarkNimbus backdoor, also referred to as DarkNights. Reporting links the cluster to long-running activity since at least 2019, with DarkNimbus development assessed to date back to at least 2018. Earth Minotaur primarily targets Tibetan and Uyghur communities, using social engineering delivered through instant messaging applications to lure victims to malicious links. MOONSHINE has been used to exploit multiple Chromium and Tencent Browser Server vulnerabilities on Android, selectively serving exploit code only to targeted vulnerable applications and browser versions. Observed lures have impersonated government announcements, health news, religion-related content, travel information, and media relevant to Tibetan and Uyghur audiences. The framework has also supported deceptive browser-engine downgrade prompts to force victims onto exploitable versions before compromise. Successful exploitation has been observed leading to installation of DarkNimbus on Android through replacement of embedded browser components with trojanized packages. The Android variant of DarkNimbus supports extensive surveillance and collection, including device profiling, contacts, SMS, call history, GPS data, clipboard contents, browser bookmarks, files, screenshots, photos, recordings, and theft of communications from messaging applications via abuse of Android accessibility features. A Windows variant written in C++ supports host profiling, installed software enumeration, file theft, browsing-history collection, screenshots, keystroke capture, clipboard theft, shell execution, and browser credential theft. Earth Minotaur has also been linked to DKnife, a modular Linux-based gateway-monitoring and adversary-in-the-middle framework deployed on routers and edge devices. DKnife supports deep packet inspection, DNS hijacking, credential harvesting from email traffic, malware delivery through hijacked binary downloads and Android application updates, reverse proxying, packet forwarding, and component maintenance. Reported payloads delivered through this ecosystem include DarkNimbus and ShadowPad. The actor is linked through tooling overlap to other China-aligned operations, but available reporting treats Earth Minotaur and TheWizards as distinct operators despite both using DarkNimbus-related tooling. MOONSHINE has been assessed as remaining under active development and may be shared with or used by multiple Chinese-aligned intrusion sets. Earth Minotaur's observed activity is consistent with politically motivated surveillance and intelligence collection focused on ethnic and community targets of interest to the Chinese state.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
Vulnerability Targeted Version CVE-2016-1646 Chrome 39~49
Vulnerability Targeted Version CVE-2016-5198 Chrome 50
Vulnerability Targeted Version CVE-2017-5030 Chrome 51~55
Vulnerability Targeted Version CVE-2017-5070 Chrome 56~58
Vulnerability Targeted Version CVE-2018-17463 Chrome 68~69
4 more CVEs tied to this actor tracked in Mallory.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Surveillance-focused cluster using the MOONSHINE exploit kit to deliver DarkNimbus backdoor to Android/Windows, targeting Tibetan and Uyghur communities (WeChat-focused per content).
China-nexus activity cluster associated with operating the DKnife adversary-in-the-middle/gateway-monitoring framework since at least 2019, leveraging router/edge-device implants for deep packet inspection, traffic manipulation, credential theft, DNS hijacking, and malware delivery (including backdoors).
China-nexus activity cluster linked to MOONSHINE exploit kit and the DarkNimbus backdoor; associated monitoring led to discovery of the DKnife AitM/gateway-monitoring framework.
Referenced as the developer of the DarkNimbus backdoor (deployed by TheWizard per the content).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.