Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CardinalLizard

Description

CardinalLizard, a cyber threat actor linked to China, has targeted entities in Asia since 2018. Their methods include spear-phishing, custom malware with anti-detection features, and potentially shared infrastructure with other actors.

AI Analysis

· 1 week ago

Executive Summary

CardinalLizard is a cyber threat actor linked to China, primarily active since 2018, targeting entities in Asia. Known for sophisticated attacks involving spear-phishing and custom malware with anti-detection features, CardinalLizard poses a significant threat to organizations in their targeted sectors.

Goals & Targeting

CardinalLizard's strategic objectives appear to include intelligence collection and espionage against critical infrastructure in Asia. Their targeting of sectors like energy and telecommunications suggests a focus on gaining access to sensitive information and disrupting operations. Typical victims are government entities, private sector organizations, and those operating within China's geopolitical interests.

Enhanced Description

CardinalLizard is a state-sponsored cyber threat group associated with China, first observed in 2018. Their primary activity involves targeting Asian entities, particularly in the energy and telecommunications sectors. The group employs advanced tactics such as spear-phishing campaigns, deployment of custom malware with anti-detection mechanisms, and potential operational sharing with other actors. CardinalLizard's attacks are designed to achieve long-term persistence and data exfiltration, aligning with broader Chinese state interests.

Key Capabilities

  • Spear-phishing campaigns
  • Custom malware development
  • Anti-detection techniques
  • Potential use of shared infrastructure with other actors

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Persistence
Data Collection

ATT&CK Techniques

T1059.003
T1055

Software / Tooling

Custom malware
Potential use of Cobalt Strike (if linked to shared tools)

Campaigns & Victims

CardinalLizard's campaigns demonstrate a focus on stealth and long-term access. They have targeted organizations in Asia since 2018, with notable operations involving energy and telecommunications sectors. Their use of custom malware indicates a high level of sophistication. No specific campaigns are publicly documented beyond their general targeting patterns.

IOC Patterns

  • Spear-phishing emails
  • Malware with anti-detection features
  • C2 infrastructure linked to known Chinese domains

Recommended Actions

  • Implement multi-factor authentication for critical systems.
  • Conduct regular phishing simulations to train employees.
  • Monitor network traffic for signs of C2 activity.
  • Use endpoint detection and response (EDR) tools to identify custom malware.

Suggested Tags

APT
espionage
China-linked
Asia-focused

Confidence Assessment

High confidence in CardinalLizard's existence, goals, and capabilities based on public reporting. Limited details on specific campaigns and techniques used outside of general TTPs. No direct attribution to concrete incidents beyond the sectors targeted.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
APT
espionage
China-linked
Asia-focused

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.