Soft Cell is a long-running China-aligned cyber-espionage activity group associated with intrusions against telecommunications providers, particularly in Southeast Asia and the broader ASEAN region. The group has been active since at least 2012, with later observed operations spanning 2018 through 2021 against high-value telecom assets including Microsoft Exchange servers, domain controllers, billing systems, and web servers. Its apparent objective is persistent access to telecom environments and theft of sensitive communications-related information, including credentials and call-detail-related data, in support of Chinese state interests. Soft Cell is known for combining exploitation of internet-facing enterprise infrastructure with extensive post-compromise tradecraft. In telecom intrusions, the group exploited Microsoft Exchange vulnerabilities and deployed web shells for foothold establishment and remote command execution. It used built-in Windows utilities for host and network reconnaissance, including discovery of network configuration and remote systems, and leveraged modified scanning tools for NetBIOS and Active Directory-related enumeration. The group has demonstrated strong credential access and lateral movement capabilities. Reported tradecraft includes dumping credentials and password hashes, including collection from the SAM hive, use of Mimikatz and PowerShell-based credential theft, abuse of valid accounts to maintain access, and movement through WMI, scheduled tasks, administrative shares, and remote execution tooling. Soft Cell has also used PowerShell extensively for execution, credential dumping, timestomping, and lateral movement, alongside direct use of the Windows command shell. Soft Cell has employed multiple stealth and persistence mechanisms. These include DLL side-loading to load malware such as PoisonIvy and PcShare through legitimate executables, deployment of web shells, installation of remote-access tooling for long-term access, scheduled-task persistence, timestomping, string obfuscation in tunneling utilities, and use of packed payloads with both commodity and custom packers. The group has also used modified proxying/tunneling tools and covert staging locations to reduce detection. For collection and exfiltration, Soft Cell has staged stolen data locally, compressed and password-protected archives, and exfiltrated data through established access channels such as web shells and tunneling utilities. Known aliases and naming variants include Soft Cell, softcell, and soft_cell. Cluster A has been assessed as activity operated by Soft Cell in telecommunications espionage operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyber espionage activity targeting telecommunications providers in Southeast Asia and other regions, using Microsoft Exchange exploitation, web shells, credential theft, lateral movement, persistence, and data exfiltration to access sensitive telecom data such as CDRs.
Uses PowerShell for execution, lateral movement, and credential dumping.
Uses DLL side-loading to covertly load PoisonIvy into memory.
Uses PowerShell for execution, lateral movement, and credential dumping.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.