IronHusky is a Chinese-origin threat actor known for targeting government entities with the MysterySnail RAT.
Analyst brief
IronHusky is a Chinese-origin threat actor first attributed in 2017, targeting Russian and Mongolian government entities, aviation companies, and research institutes. After their initial attacks ceased in 2018, the group has been developing a new remote access trojan named MysterySnail. Defenders should focus on detecting suspicious C2 traffic linked to MysterySnail and potential spear-phishing campaigns aimed at government or research targets.
IronHusky
unknown
IronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research institutes. Since their initial attacks ceased in 2018, they have been working on a new remote access trojan dubbed MysterySnail.
Which countries' government entities has IronHusky targeted?+
IronHusky has primarily targeted Russian and Mongolian government entities.
What activities related to MysterySnail should defenders focus on?+
Defenders should focus on detecting suspicious C2 traffic linked to MysterySnail and potential spear-phishing campaigns aimed at government or research targets.