Skip to content
skopnix
← adversaries
Unknown · assessed origin China

Teleboyi

misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

Teleboyi is a threat actor reportedly based in China, associated with the PlugX RAT. TeamT5 identified a custom PlugX loader used by Teleboyi that employs a similar string decryption algorithm as seen in the McUtil.dll loader from Operation Harvest. While there are weak links to the dsqurey[.]com domain, the connection remains uncertain due to the domain's registration history.

Take it with you
References
Early access

Track Teleboyi on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected