KeyBoy is a Chinese advanced persistent threat designation associated with espionage activity primarily targeting organizations in East Asia. It has been discussed as related to TA428, Pirate Panda, and Tropic Trooper, with reported tradecraft overlap also noted with Royal Road Group-B activity clusters such as Tick and Tonto. The available reporting supports treating KeyBoy as part of a broader Chinese intrusion ecosystem focused on government targets. Activity associated with this cluster has used spearphishing documents themed around geopolitical and public-health topics to gain initial access, including Microsoft Word exploitation of CVE-2018-0798. Post-compromise behavior includes persistence through malicious Word add-ins, deployment of Poison Ivy and Cotx RAT, DLL sideloading using legitimate signed executables, credential theft from Outlook and LSASS, internal reconnaissance, and lateral movement using tooling derived from public MS17-010 scanning and exploitation code. Operators have also injected malware into LSASS, deployed additional remote access trojans including Tmanger and nccTrojan, and used capabilities such as command execution, file operations, screen capture, keylogging, and remote shell access. The actor demonstrates mature post-exploitation tradecraft, including defense evasion, process injection, persistence, and multi-stage malware deployment against government organizations in East Asia.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.