Also known as: Shaoye, Roaming Mantis Group
**Targets:** Russia, Japan, India, Bangladesh, Kazakhstan, Azerbaijan, Iran, and Vietnam **Toolset/Malware:** Malicious APK
Targeted Countries / Regions
Executive Summary
Roaming Mantis, also known as Shaoye, is a nation-state threat actor primarily involved in espionage activities targeting key sectors such as technology, defense, and government in countries like Russia, Japan, India, and Iran. The group employs sophisticated tactics, including the use of malicious APKs for mobile device compromise, and has demonstrated persistence in global operations over several years.
Goals & Targeting
Roaming Mantis's strategic objectives center on espionage and intelligence gathering, particularly from targeted sectors in specific countries. Their focus on regions like Russia, Japan, India, and Iran suggests a geopolitical agenda, possibly linked to surveillance or competitive advantage. The group's victims typically include government entities, defense companies, and technology firms, indicating a proactive approach to data collection for strategic gain.
Enhanced Description
Roaming Mantis, identified by aliases including Shaoye, operates as a state-sponsored threat group with a primary focus on espionage. The actor is known to target critical sectors such as technology, defense, and government across multiple countries, including Russia, Japan, India, Iran, and others. Their operational手法 includes the deployment of malicious APKs targeting mobile devices, indicative of their ability to compromise endpoints and gather sensitive information. While the exact origin of Roaming Mantis remains unclear, their activities suggest a high degree of sophistication, likely associated with a nation-state-sponsored program.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Roaming Mantis has been observed conducting long-term campaigns targeting high-value assets in multiple countries. Their operational tempo is inconsistent but suggests a patient and deliberate approach to compromising targets. Campaigns often involve the distribution of malicious software via phishing attacks, with a focus on infiltrating government and defense sector organizations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Roaming Mantis's nation-state affiliation, but some details about their exact origin remain speculative. Limited visibility into their specific TTPs in certain regions and sectors creates gaps in understanding their full capabilities.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics