14K Triad is a Chinese organized crime syndicate and triad group. It has been associated with transnational criminal activity in Asia and has been linked in reporting and testimony to cyber-enabled scam ecosystems operating from Southeast Asia. The group is notable in this context through its former leadership connection to Wan Kuok-Koi, also known as Broken Tooth, who was identified as a former head of the 14K triad and later re-emerged as a businessman with influence in regional criminal networks. Available information in this record ties the group to broader Chinese criminal syndicate activity surrounding scam compounds, but does not provide sufficiently specific, high-confidence detail to attribute a distinct cyber intrusion tradecraft profile, malware set, or ransomware program directly to 14K itself. Based on the available facts, 14K should be characterized primarily as an organized crime actor with alleged involvement in fraud-linked transnational operations rather than a clearly delineated standalone cyber threat cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.