Taihe Gong is a Chinese-speaking cybercriminal scamming group associated with the Chinese underground fraud ecosystem. It has been identified as one of the criminal entities purchasing and using Lighthouse phishing kits, indicating participation in phishing-enabled fraud operations supported by crime-as-a-service infrastructure. The group operates within a broader Chinese-language scam environment characterized by industrialized social-engineering activity, phishing-as-a-service tooling, and cryptocurrency-enabled monetization. High-confidence reporting supports that Taihe Gong is composed of Chinese-language operators and is linked to financially motivated scam activity rather than state-directed espionage. Publicly available information in this context does not establish distinct sub-groups, ransomware operations, or a more specific victimology for Taihe Gong beyond its role in phishing and fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
中国語話者オペレーターからなる詐欺クラスター。Lighthouseフィッシングキット等の詐欺インフラを購入・活用し、詐欺的サイバー犯罪活動(フィッシングキット流通を含む)に関与している疑い。CMLNやfraud shop等の地下エコシステムと資金的な結びつきが示唆される。
Chinese-speaking underground scamming entity associated with purchasing/reselling phishing kits and supporting online scam/credential-theft enablement within a broader Chinese-language criminal ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.