TA428, also tracked as BRONZE DUDLEY, Temp.Hex, and Vicious Panda, is a China-linked espionage threat actor. The group has been assessed as operating on behalf of China with moderate confidence and is associated with intelligence-collection activity rather than financially motivated crime. TA428 has used weaponized RTF documents for initial compromise and has deployed the PoisonIvy remote access trojan in intrusions. Tooling associated with the cluster also includes Royal Road, PhantomNet, and NCCTrojan. Observed targeting includes entities in Mongolia, with additional reporting indicating government and commercial organizations in East Asia may also be targeted. The actor is tracked separately from, but may overlap with, BRONZE PRESIDENT and BRONZE HUNTLEY.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese espionage threat group profiled in the listing.
Espionage activity cluster assessed (moderate confidence) to operate on behalf of China; uses weaponized RTF documents to deliver the PoisonIvy RAT against government and commercial targets, with observed targeting in Mongolia and broader East Asia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.