Obstinate Mogwai is an Asian advanced persistent threat group identified by Solar 4RAYS during an investigation into the compromise of a Russian telecommunications company in late 2023. Its presence was also identified in a government organization's compromised infrastructure in 2025. Its specific country of origin, state affiliation, and relationship to established APT groups have not been reliably established. Donnect malware is associated with the group. Obstinate Mogwai exploits ASP.NET VIEWSTATE deserialization on Microsoft Exchange servers using compromised application validation keys. This technique enabled repeated access after responders removed externally accessible web shells. Its custom VIEWSTATE Exploitation Framework uses standard ysoserial gadgets to load .NET assemblies into Exchange worker-process memory, submitting a separate assembly-bearing request for each action. The framework supports PowerShell execution without launching a separate PowerShell process, file and directory inspection, and file exfiltration. The group has stolen mailbox contents and other data through compromised Exchange servers. Observed activity includes account enumeration, directory discovery, registry queries, connectivity checks, DNS resolution, additional tool deployment, and file deletion. The group also uses obfuscated PowerShell to decrypt and load a .NET backdoor into memory. Memory-resident execution and encrypted command inputs and responses reduce exposure to disk-based detection. Obstinate Mogwai is tracked separately from Erudite Mogwai, also known as Space Pirates; their presence in the same victim environments does not establish a shared identity or operational relationship.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named APT cluster reported present on a Russian organization’s network (per Rostelecom security team reporting).
Obstinate Mogwai was present in the compromised infrastructure of the Russian government organization alongside other groups. The article provides no specific operational details, country attribution, or explicit connection between this group and ShadowRelay.
Связана с обнаружением Donnect; в период предполагаемой активности на Exchange/в инфраструктуре размещен новый модульный бэкдор ShadowRelay, но атрибуция ShadowRelay этой группе не подтверждена.
An Asian threat group discussed as a technical comparison with Shedding Zmiy. It exploits ASP.NET VIEWSTATE deserialization using standard ysoserial gadgets and conventional web-shell injection and activation techniques. Unlike BADSTATE's reusable memory-resident web shell, its framework loads an assembly into memory for each command. The reference does not identify specific countries of origin, sponsorship, or targeting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.