Unknown · assessed origin China
Teleboyi
misp-galaxyrefreshed 2026-09-15
sigil
Analyst brief
Teleboyi is a threat actor reportedly based in China, associated with the PlugX RAT. TeamT5 identified a custom PlugX loader used by Teleboyi that employs a similar string decryption algorithm as seen in the McUtil.dll loader from Operation Harvest. While there are weak links to the dsqurey[.]com domain, the connection remains uncertain due to the domain's registration history.
Early access
Track Teleboyi on the wire.
Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.
bot-protected