IronHusky is a Chinese-speaking cyber espionage group first observed in mid-2017, operating with a primary motivation of information theft and espionage, particularly focusing on tracking geopolitical agendas. The group initially leveraged common Remote Access Trojans (RATs) such as PlugX and PoisonIvy but has since evolved its custom malware capabilities, notably developing and continuously upgrading the MysterySnail RAT and its streamlined variant, MysteryMonoSnail. IronHusky is distinguished by its focused targeting of a specific geopolitical agenda, shifting its attention from Russian military contractors to Mongolian government entities in early 2018. The group has also been identified by the alias BBCY-TA1.