CSIDB logo
Threat actor

LuckyCat

Attribution profile

Type
Nation State
Location
China
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-17 05:26
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

LuckyCat, also tracked as Naikon, is a Chinese‑language advanced persistent threat group that has been active since at least 2010 and is widely described by security researchers as a state‑sponsored espionage actor. The group’s aliases appear in multiple threat‑intelligence reports, and its activity has been linked to interests aligned with the People’s Republic of China, although no official governmental attribution has been publicly confirmed. Observers have noted that LuckyCat’s operations focus on gathering intelligence rather than financial gain, with its campaigns primarily targeting governmental and military entities in the South China Sea region.

The group’s typical targets include ministries of defense, foreign affairs, telecommunications authorities, and state‑owned oil and gas companies in countries such as Vietnam, the Philippines, Brunei, Malaysia, and Cambodia. These sectors are chosen because they contain sensitive information related to territorial disputes, maritime security, and national defense, which aligns with the espionage motive that analysts attribute to LuckyCat. There is little public evidence to suggest the group engages in financially motivated cybercrime; its activities are consistently described as intelligence‑gathering operations aimed at gaining strategic insight into regional rivals.

LuckyCat’s tactics, techniques, and procedures have been observed across several campaigns. The group frequently initiates attacks through spear‑phishing emails that contain malicious Rich Text Format (RTF) files exploiting known vulnerabilities such as CVE‑2012‑0158 (MSCOMCTL.OCX). Once a victim opens the attachment, the attackers deploy remote‑access tools including the Poison Ivy and PlugX families, as well as a custom malware referred to in reporting as Hightide. Persistence mechanisms have been noted to involve the use of legitimate credentials and web shells, allowing the actors to maintain long‑term access to compromised networks. While watering‑hole techniques have been mentioned in some analyses, the primary and most consistently reported initial access vector remains the spear‑phishing route with malicious document exploits.

Notable operations attributed to LuckyCat include the series of intrusions collectively referred to as Operation Naikon, which targeted the Vietnamese Ministry of National Defense, the Philippine Department of Foreign Affairs, the Brunei Ministry of Defence, and the Malaysian Ministry of Defense, among others. In later years, the group has been observed extending its focus to Taiwanese government agencies and occasional entities in Europe and the United States, often employing PlugX payloads to exfiltrate documents and emails. Security firms such as Kaspersky, Symantec, and FireEye have published analyses linking the group’s infrastructure and malware to Chinese‑based actors, with some assessments suggesting a connection to the Guangdong provincial government or the PLA’s Southern Theater Command, though these remain analyst‑derived attributions rather than formal state declarations.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB