Yanbian Gang is a Chinese cybercriminal threat actor active since at least 2013 and associated with operations from Yanbian Prefecture in Jilin Province, China. The group is linked to Android-focused financially motivated campaigns involving the Roaming Mantis ecosystem and malware including Moqhao, also known as Shaoye or XLoader, and has also been correlated with FakeSpy activity. Reporting has tied the actor to large-scale mobile malware operations targeting users through SMS phishing campaigns, especially messages themed as parcel-delivery notifications or fake updates for popular applications. The group’s operations center on infecting Android devices to steal sensitive information and financial data, install additional applications, and abuse compromised devices to propagate further smishing messages. Yanbian Gang activity has been particularly associated with theft affecting South Korean bank customers and broader targeting of online banking users in South Korea and Japan. Evidence also links the actor to campaigns with substantial victimization in Japan and South Korea, with additional infection activity observed in Germany. A notable capability associated with the actor’s Moqhao tooling is the compromise of consumer routers to facilitate DNS hijacking. The malware can identify router administration interfaces, fingerprint supported router models, locate login forms and CAPTCHA challenges, use OCR-based solving of text CAPTCHAs, and conduct brute-force attempts with default or weak credentials. After obtaining administrative access, it can alter DNS settings to redirect victims toward attacker-controlled phishing or malware-delivery infrastructure. This router-focused activity has been reported as especially concentrated on Asia-linked router models and primarily focused on South Korea. Infrastructure tradecraft attributed to the actor includes use of social media profiles to conceal or distribute operational configuration such as command-and-control and auxiliary service details. Code, behavioral, and infrastructure overlaps have also been observed between XLoader and FakeSpy, with shared deployment patterns and domain-registration links pointing to Jilin Province. While some reporting allows for the possibility of shared services or affiliated operators, Yanbian Gang is consistently characterized as a Chinese cybercriminal actor engaged in mobile malware, credential and information theft, banking fraud, smishing, brute-force router compromise, and DNS hijacking.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android-focused cybercriminal group behind the Roaming Mantis malware family, using Moqhao for SMiShing, malware delivery, device takeover, DNS hijacking, and router compromise via CAPTCHA bypass and brute-force attacks.
A Chinese cybercriminal group potentially connected to the operators of FakeSpy and XLoader. It is described as being infamous for stealing money from South Korean bank account holders, and its malware/code overlaps with FakeSpy samples.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.