HenBox
Linked to China by two sources.
Reports per quarter
Techniques seen in the last two years
- T1003.001 1 report
- T1008 1 report
- T1016 1 report
- T1021.002 1 report
- T1027.001 1 report
- T1027.002 1 report
- T1033 1 report
- T1036.004 1 report
- T1036.005 1 report
- T1040 1 report
Show all 53 techniques Show fewer
- T1053.002 1 report
- T1053.005 1 report
- T1055 1 report
- T1055.001 1 report
- T1056.001 1 report
- T1057 1 report
- T1059.003 1 report
- T1059.005 1 report
- T1068 1 report
- T1069.002 1 report
- T1071.001 1 report
- T1071.004 1 report
- T1078.002 1 report
- T1082 1 report
- T1083 1 report
- T1087.001 1 report
- T1087.002 1 report
- T1090.001 1 report
- T1095 1 report
- T1105 1 report
- T1106 1 report
- T1112 1 report
- T1119 1 report
- T1132.001 1 report
- T1140 1 report
- T1197 1 report
- T1218.011 1 report
- T1543.003 1 report
- T1546.015 1 report
- T1547.001 1 report
- T1548.002 1 report
- T1553.002 1 report
- T1555.003 1 report
- T1560.001 1 report
- T1564.001 1 report
- T1566.001 1 report
- T1566.002 1 report
- T1569.002 1 report
- T1571 1 report
- T1572 1 report
- T1573.001 1 report
- T1614.001 1 report
- T1620 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2017-0213 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Space Pirates analyzing the tools and connections of a new hacker group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Pirates analyzing the tools and connections of a new hacker group
-
Multiyear Surveillance Campaigns Discovered Targeting Uyghurs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Multiyear Surveillance Campaigns Discovered Targeting Uyghurs
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor lookout-uyghur-malware-tr-us
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pulling the PKPLUG- the adversary playbook for the long-standing espionage activity of a Chinese nation-state adversary
-
PKPLUG_ Chinese Cyber Espionage Group Attacking Asia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PKPLUG_ Chinese Cyber Espionage Group Attacking Asia
-
PKPLUG- Chinese Cyber Espionage Group Attacking Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PKPLUG- Chinese Cyber Espionage Group Attacking Asia
Show all 15 reports Show fewer
-
Farseer- Previously Unknown Malware Family bolsters the Chinese armoury
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Farseer- Previously Unknown Malware Family bolsters the Chinese armoury
-
HenBox- The Chickens Come Home to Roost
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HenBox- The Chickens Come Home to Roost
Newest first. Details opens the report in Explore.