Researchers documented Hellsing, an espionage group active across the Asia-Pacific region, after an unusual incident in which a recipient of a Naikon spear-phishing email sent back a weaponized archive that infected the original operators. The campaign primarily targeted organizations in Malaysia, the Philippines, and Indonesia, especially around the South China Sea, using spear-phishing messages with RAR, ZIP, and 7ZIP attachments to deliver custom backdoors including msger and xweber.
The malware set also included tools such as xrat, clare, irene, test.exe, diskfilter.sys, and xKat for victim profiling, proxy testing, lateral movement, and removing rival implants from compromised systems. Infrastructure and protocol overlaps linked the activity to other China-associated espionage clusters, while separate reporting highlighted BKDR_RARSTONE as another remote-access trojan to watch, reinforcing concern over archive-based malware delivery and custom RAT development in regional cyber-espionage operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Securelist published a report detailing Hellsing as a distinct espionage operation active in the Asia-Pacific region, including its targeting, malware families, and infrastructure overlaps with other China-linked clusters.
By March 11, 2014, Naikon was targeting nations involved in the search for MH370, including high-level government, military, intelligence, aviation, justice, and police entities.
In March 2014, Naikon began a major operation in the wake of the MH370 disappearance, using spear-phishing documents exploiting CVE-2012-0158 to deploy its RARSTONE backdoor against governments and related institutions.
Analysis of the backdoor delivered to the Naikon operator led researchers to name the actor behind the counterattack "Hellsing." The malware connected to philippinenews[.]mooo[.]com and supported file transfer, self-update, and uninstall functions.
After receiving a Naikon spear-phishing email, one target replied to verify its authenticity, received a follow-up impersonating an internal secretariat employee, and later sent back a password-protected RAR archive containing decoy PDFs and a malicious SCR file aimed at the Naikon operator.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.