Uptime Hamster: 10d 8h 9mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Lucky Cat

Lucky Cat

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: TA413, White Dev 9, Shadow Network, SabPub, TA413 (Proofpoint), ENDTRADE, otros, operaciones de sabotaje, exilerat, luckycat, sepulcher, shadownet, ta413
Ver en IntelTracker → APTTrail →
Lucky Cat is a cyber espionage group, assessed with high confidence to be state-sponsored by China, that emerged with documented activity starting in April 2011. While initially recognized for targeting military research and shipping industries, the group, also known as TA413 and White Dev 9, has consistently focused on the Tibetan community globally for intelligence gathering and surveillance. A defining characteristic of Lucky Cat is its ability to blend the use of established toolsets, such as the Royal Road RTF weaponizer, with the rapid adoption of newly discovered zero-day vulnerabilities in its campaigns. The group primarily aims to exfiltrate sensitive information.

Aliases del actor

TA413White Dev 9Shadow NetworkSabPubTA413 (Proofpoint)ENDTRADEotrosoperaciones de sabotajeexileratluckycatsepulchershadownetta413

Actores similares

Network Devicesactor · 1lucky-catactor · 1ShadowSyndicateapt · 0Shadow Networkapt · 0devmanransomware · 184shadowbyt3actor · 130day-syndicateactor · 5blackshadowransomware · 2hellcatransomware · 2madcatransomware · 2

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownduckduckgo.comLucky Cat (China)
DLS / leak siteunknownduckduckgo.comLucky Cat (China)
Motivacion