SteppeDriver is a China-aligned cyber espionage cluster first identified in 2024. It has been observed targeting government-related entities and other organizations in multiple regions, including France, Mongolia, South America, and Syria. Reported activity against a Syrian governmental network has been assessed as consistent with Chinese strategic interests, including reconstruction-related commercial priorities and security concerns tied to Uyghur militants in Syria. The cluster has used a toolset that includes ShadowPad, COOLCLIENT, CurlyDoor, RudeGull, and MKTDownloader. Its operations are associated with intrusion tradecraft typical of Chinese espionage activity, including malware deployment for sustained access and follow-on post-compromise operations. Based on the reported tooling and victimology, SteppeDriver should be understood as an espionage-focused actor rather than a financially motivated or ransomware-oriented group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-aligned activity cluster targeting entities in France, Mongolia, and South America using multiple malware tools.
Targeted a Syrian governmental network in an apparent espionage operation aligned with Chinese commercial and security interests.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.