Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Roaming Mantis

Also known as: Shaoye, Roaming Mantis Group

Description

**Targets:** Russia, Japan, India, Bangladesh, Kazakhstan, Azerbaijan, Iran, and Vietnam **Toolset/Malware:** Malicious APK

Goals & Targeting

Targeted Countries / Regions

RU
JP
IN
IR

AI Analysis

· 1 week ago

Executive Summary

Roaming Mantis, also known as Shaoye, is a nation-state threat actor primarily involved in espionage activities targeting key sectors such as technology, defense, and government in countries like Russia, Japan, India, and Iran. The group employs sophisticated tactics, including the use of malicious APKs for mobile device compromise, and has demonstrated persistence in global operations over several years.

Goals & Targeting

Roaming Mantis's strategic objectives center on espionage and intelligence gathering, particularly from targeted sectors in specific countries. Their focus on regions like Russia, Japan, India, and Iran suggests a geopolitical agenda, possibly linked to surveillance or competitive advantage. The group's victims typically include government entities, defense companies, and technology firms, indicating a proactive approach to data collection for strategic gain.

Enhanced Description

Roaming Mantis, identified by aliases including Shaoye, operates as a state-sponsored threat group with a primary focus on espionage. The actor is known to target critical sectors such as technology, defense, and government across multiple countries, including Russia, Japan, India, Iran, and others. Their operational手法 includes the deployment of malicious APKs targeting mobile devices, indicative of their ability to compromise endpoints and gather sensitive information. While the exact origin of Roaming Mantis remains unclear, their activities suggest a high degree of sophistication, likely associated with a nation-state-sponsored program.

Key Capabilities

  • State-sponsored espionage
  • Development and deployment of malicious APKs
  • Spear-phishing campaigns targeting mobile devices
  • Persistence and lateral movement within victim networks

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Execution
Persistence
Exfiltration

ATT&CK Techniques

T1059
T1059.003
T1566.001
T1078.004
T1284

Software / Tooling

Malicious APKs
Custom malware for mobile platforms

Campaigns & Victims

Roaming Mantis has been observed conducting long-term campaigns targeting high-value assets in multiple countries. Their operational tempo is inconsistent but suggests a patient and deliberate approach to compromising targets. Campaigns often involve the distribution of malicious software via phishing attacks, with a focus on infiltrating government and defense sector organizations.

IOC Patterns

  • Spear-phishing emails delivering malicious APK attachments
  • Mobile device infections from known Roaming Mantis campaigns
  • Lateral movement within networks using custom tools

Recommended Actions

  • Implement robust mobile security solutions to detect and block malicious APKs.
  • Conduct regular phishing simulations to train employees on identifying spear-phishing attempts.
  • Monitor for异常 network traffic indicative of espionage activities.
  • Enhance endpoint detection and response capabilities to identify and mitigate malicious activity.

Suggested Tags

APT
espionage
mobile-targeted
state-sponsored

Confidence Assessment

High confidence in Roaming Mantis's nation-state affiliation, but some details about their exact origin remain speculative. Limited visibility into their specific TTPs in certain regions and sectors creates gaps in understanding their full capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
mobile-targeted
state-sponsored

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.