PT_Moisha
Attribution profile
- Type
- Criminal
- Location
- China
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2022-09-28
- Last seen
- 2022-09-28
- Updated
- 2026-08-01 19:23
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
PT_Moisha, also known as Moisha, is a ransomware group that has been observed operating from China. The group first came to public attention in September 2022 when it claimed responsibility for an attack on Aoyuan Healthy Life Group, a subsidiary of the China Aoyuan Group that maintains offices in Hong Kong, Australia and Canada. In that incident PT_Moisha described itself as an established threat actor despite being newly identified in the public record. The attackers used the secure messaging platform qTox to communicate with a journalist and to provide proof of the breach. They asserted that they had exfiltrated approximately 200 gigabytes of documents from the victim’s network, sharing a 200‑megabyte sample as evidence. The activity was characterized as a ransomware attack, indicating the group’s use of encryption and extortion tactics.
Beyond the Aoyuan Healthy Life Group incident, no additional campaigns or tools have been publicly attributed to PT_Moisha in the available sources. The group’s known tactics involve the use of qTox for communication, the exfiltration of large volumes of data, and the deployment of ransomware. Specific malware families, initial access vectors, or supplementary tooling were not disclosed in the reporting. The group described itself as an established threat actor despite being newly identified, and claimed to have exfiltrated a large volume of data. Attribution to a particular state sponsor or criminal consortium has not been made public, and the only geographic clue is the stated location in China. Consequently, the public profile of PT_Moisha remains limited to the single reported ransomware event and the associated TTPs that were explicitly mentioned.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.