Also known as: Shadow Network, SabPub, TA413, White Dev 9
**Targets:** A threat actor targets computer networks associated with Tibetan activists, as well as military research and development, aerospace, engineering, and shipping industries in India and Japan.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Lucky Cat, a nation-state threat actor linked to espionage activities, targets Tibetan activists and critical sectors in Japan and India, including aerospace, defense, and research. Operating under aliases such as Shadow Network and TA413, this group employs sophisticated tactics to infiltrate high-value organizations, seeking to exfiltrate sensitive military and technological data. Their operations suggest a strategic focus on geopolitical and technological intelligence gathering.
Goals & Targeting
Lucky Cat's primary objective is espionage, with a strategic focus on acquiring sensitive military and technological intelligence. The group's targeting of aerospace, defense, and research sectors in Japan and India, alongside Tibetan activist networks, indicates an intent to disrupt strategic initiatives, steal proprietary information, and monitor geopolitical movements. The selection of Japan and India as key targets likely reflects their significance in regional security and technological innovation, with the actor aiming to gain insights that could be leveraged for diplomatic or military advantage. Tibetan activists are likely targeted to suppress dissent and gather intelligence on movements advocating for autonomy, aligning with broader nation-state objectives in the region.
Enhanced Description
Lucky Cat, also known as Shadow Network, SabPub, TA413, and White Dev 9, is a highly sophisticated nation-state actor primarily engaged in espionage against Tibetan activists and organizations in Japan and India. Their targets span military research, aerospace, engineering, and shipping sectors, indicating a deliberate effort to undermine technological and defense capabilities in these regions. The actor's operations are characterized by a focus on intellectual property theft and the collection of strategic military intelligence, leveraging advanced persistent threat (APT) techniques to maintain long-term access to victim networks. While specific technical details are limited, the group's targeting pattern aligns with nation-state actors seeking to support geopolitical objectives, particularly in regions with complex security dynamics such as South and East Asia. Their use of stealthy operations and targeted attacks suggests a high degree of operational discipline and resource allocation.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Lucky Cat's campaigns are characterized by a targeted, low-and-slow approach, focusing on high-value sectors and individuals. Operations often begin with spear-phishing emails containing malicious documents or exploit payloads, followed by network infiltration and long-term surveillance. The actor has not been linked to public campaigns, suggesting operations are conducted covertly to avoid attribution. Notable patterns include the use of geographically proximate infrastructure for command and control, as well as the exploitation of local supply chain vulnerabilities in Japan and India.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the threat actor's profile is moderate, based on the limited public data available. While the targeting sectors and nation-state attribution are well-supported, specific technical details (e.g., MITRE techniques, toolset, campaign timelines) remain inferred due to gaps in the provided intelligence. Further analysis of network traffic and forensic data from affected organizations could enhance the accuracy of capabilities and TTPs.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics