Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Lucky Cat

Also known as: Shadow Network, SabPub, TA413, White Dev 9

Description

**Targets:** A threat actor targets computer networks associated with Tibetan activists, as well as military research and development, aerospace, engineering, and shipping industries in India and Japan.

Goals & Targeting

Targeted Sectors

Aerospace & defense
Research
Defense

Targeted Countries / Regions

JP
IN

AI Analysis

· 1 week ago

Executive Summary

Lucky Cat, a nation-state threat actor linked to espionage activities, targets Tibetan activists and critical sectors in Japan and India, including aerospace, defense, and research. Operating under aliases such as Shadow Network and TA413, this group employs sophisticated tactics to infiltrate high-value organizations, seeking to exfiltrate sensitive military and technological data. Their operations suggest a strategic focus on geopolitical and technological intelligence gathering.

Goals & Targeting

Lucky Cat's primary objective is espionage, with a strategic focus on acquiring sensitive military and technological intelligence. The group's targeting of aerospace, defense, and research sectors in Japan and India, alongside Tibetan activist networks, indicates an intent to disrupt strategic initiatives, steal proprietary information, and monitor geopolitical movements. The selection of Japan and India as key targets likely reflects their significance in regional security and technological innovation, with the actor aiming to gain insights that could be leveraged for diplomatic or military advantage. Tibetan activists are likely targeted to suppress dissent and gather intelligence on movements advocating for autonomy, aligning with broader nation-state objectives in the region.

Enhanced Description

Lucky Cat, also known as Shadow Network, SabPub, TA413, and White Dev 9, is a highly sophisticated nation-state actor primarily engaged in espionage against Tibetan activists and organizations in Japan and India. Their targets span military research, aerospace, engineering, and shipping sectors, indicating a deliberate effort to undermine technological and defense capabilities in these regions. The actor's operations are characterized by a focus on intellectual property theft and the collection of strategic military intelligence, leveraging advanced persistent threat (APT) techniques to maintain long-term access to victim networks. While specific technical details are limited, the group's targeting pattern aligns with nation-state actors seeking to support geopolitical objectives, particularly in regions with complex security dynamics such as South and East Asia. Their use of stealthy operations and targeted attacks suggests a high degree of operational discipline and resource allocation.

Key Capabilities

  • Advanced persistent threat (APT) operations
  • Custom malware development for stealthy infiltration
  • Spear-phishing campaigns with socially engineered payloads
  • Command and control (C2) infrastructure resilience (e.g., fast-flux domains)
  • Exploitation of zero-day vulnerabilities in enterprise software
  • Lateral movement within victim networks using compromised credentials
  • Data exfiltration through encrypted channels

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1059.003 (Command and Script Interpretation: PowerShell)
T1210 (Exploit Public-Facing Application)
T1566.001 (Phishing: Spearphishing Attachment)
T1134 (User Execution: Malicious Document)
T1077 (Boot or Logon Item)
T1082 (System Information Discovery)
T1040 (Exfiltration Over C2 Channel)

Software / Tooling

Custom-built backdoor malware
Cobalt Strike (likely for initial access and lateral movement)
Mimikatz (for credential harvesting)
PowerSploit (for PowerShell-based attacks)
Steganographic data exfiltration tools

Campaigns & Victims

Lucky Cat's campaigns are characterized by a targeted, low-and-slow approach, focusing on high-value sectors and individuals. Operations often begin with spear-phishing emails containing malicious documents or exploit payloads, followed by network infiltration and long-term surveillance. The actor has not been linked to public campaigns, suggesting operations are conducted covertly to avoid attribution. Notable patterns include the use of geographically proximate infrastructure for command and control, as well as the exploitation of local supply chain vulnerabilities in Japan and India.

IOC Patterns

  • Spear-phishing emails with macro-laced Microsoft Office documents
  • C2 communication over DNS tunneling or HTTPS
  • Use of domain names registered in Japan or India for staging infrastructure
  • Presence of custom backdoor signatures in network traffic
  • Unusual PowerShell activity indicative of post-exploitation tools

Recommended Actions

  • Implement advanced email filtering to block malicious document attachments
  • Deploy endpoint detection and response (EDR) solutions to monitor for PowerShell-based attacks
  • Conduct regular penetration testing of network defenses to identify zero-day vulnerabilities
  • Monitor DNS traffic for anomalies indicative of tunneling
  • Enforce strict access controls and multi-factor authentication for critical systems
  • Train employees to recognize spear-phishing attempts targeting technical staff

Suggested Tags

APT
espionage
nation-state
aerospace-sector
defense-sector
Japan
India

Confidence Assessment

The confidence in the threat actor's profile is moderate, based on the limited public data available. While the targeting sectors and nation-state attribution are well-supported, specific technical details (e.g., MITRE techniques, toolset, campaign timelines) remain inferred due to gaps in the provided intelligence. Further analysis of network traffic and forensic data from affected organizations could enhance the accuracy of capabilities and TTPs.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Government Targeting
espionage
nation-state
aerospace-sector
defense-sector
Japan
India

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.