LuckyCat is a Chinese cyber-espionage campaign and associated malware cluster active since at least 2012. It has been linked to operations targeting U.S.-based activists and organizations, Tibetan activists and the broader Tibetan community, as well as Indian and Japanese military research entities. Later reporting connected LuckyCat-related infrastructure and delivery patterns to Chinese-linked activity targeting Tibetan civil society and members of the Tibetan leadership in exile, including overlap with campaigns involving ExileRAT and actor tracking under TA413. LuckyCat has also been associated with Android malware used against the international Tibetan community. The activity is characterized by targeted phishing and malware delivery in support of intelligence collection. Corroborated reporting ties LuckyCat to campaigns using malicious document attachments and remote-access tooling for victim surveillance and control. Related operations have shown overlap with Chinese APT tradecraft, including spearphishing against civil society and policy targets, use of malware for host reconnaissance and file access, and persistence mechanisms consistent with long-term espionage objectives. The actor’s victimology and operational overlaps strongly indicate a China-linked espionage mission focused on dissidents, activists, and strategic research targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked cyber-espionage campaign targeting activists and military research organizations, including Tibetan activists and Indian/Japanese military research, for intelligence collection.
Cyber-espionage campaign targeting activists and military research organizations, including Tibetan activists and Indian/Japanese military research, consistent with intelligence collection objectives.
China-attributed cyber-espionage campaign targeting activists and military research entities, including Tibetan activist communities and military research in India and Japan.
China-linked cyber-espionage campaign targeting activists and military research entities, including Tibetan activists and Indian/Japanese military research, for intelligence collection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.