Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-08

MoYu Group

As of 2026-08-25, MoYu Group is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. ATT&CK coverage spans 43 techniques across 18 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1071.001 (Web Protocols), T1082 (System Information Discovery).

Tracked threats
33 high
First seen
2026-08-21
Last seen
2026-08-25
ATT&CK techniques
43across 3 of 3 threats
Related CVEs
0None referenced
Attribution
ChinaNation or origin
Nation: China · 3 tracked threat(s) · Categories: MALWARE

Activity timeline

MoYu Group appears in 3 tracked threats between and .

ATT&CK techniques observed

43 techniques observed across 3 of 3 tracked threats · Command and Control (6), Resource Development (5), Defense Evasion (Mobile) (4), Stealth (formerly Defense Evasion) (4), Command and Control (Mobile) (3), Discovery (3)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1090.002 External Proxy — Command and Controlobserved in 2 of 3 tracked threats
  • T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 2 of 3 tracked threats
  • T1406 Obfuscated Files or Information — Defense Evasion (Mobile)observed in 2 of 3 tracked threats
  • T1407 Download New Code at Runtime — Defense Evasion (Mobile)observed in 2 of 3 tracked threats
  • T1422 System Network Configuration Discovery — Discovery (Mobile)observed in 2 of 3 tracked threats
  • T1426 System Information Discovery — Discovery (Mobile)observed in 2 of 3 tracked threats
  • T1437 Application Layer Protocol — Command and Control (Mobile)observed in 2 of 3 tracked threats
  • T1474 Supply Chain Compromise — Initial Access (Mobile)observed in 2 of 3 tracked threats
  • T1604 Proxy Through Victim — Defense Evasion (Mobile)observed in 2 of 3 tracked threats
  • T1620 Reflective Code Loading — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1643 Generate Traffic from Victim — Impact (Mobile)observed in 2 of 3 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 1 of 3 tracked threats

Tracked threats