CSIDB logo
Threat actor

PT_Moisha

Attribution profile

Type
Criminal
Location
China
Known incidents
1 incident
Sources
1 source
First seen
2022-09-28
Last seen
2022-09-28
Updated
2026-08-01 19:23
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

PT_Moisha, also known as Moisha, is a ransomware group that has been observed operating from China. The group first came to public attention in September 2022 when it claimed responsibility for an attack on Aoyuan Healthy Life Group, a subsidiary of the China Aoyuan Group that maintains offices in Hong Kong, Australia and Canada. In that incident PT_Moisha described itself as an established threat actor despite being newly identified in the public record. The attackers used the secure messaging platform qTox to communicate with a journalist and to provide proof of the breach. They asserted that they had exfiltrated approximately 200 gigabytes of documents from the victim’s network, sharing a 200‑megabyte sample as evidence. The activity was characterized as a ransomware attack, indicating the group’s use of encryption and extortion tactics.

Beyond the Aoyuan Healthy Life Group incident, no additional campaigns or tools have been publicly attributed to PT_Moisha in the available sources. The group’s known tactics involve the use of qTox for communication, the exfiltration of large volumes of data, and the deployment of ransomware. Specific malware families, initial access vectors, or supplementary tooling were not disclosed in the reporting. The group described itself as an established threat actor despite being newly identified, and claimed to have exfiltrated a large volume of data. Attribution to a particular state sponsor or criminal consortium has not been made public, and the only geographic clue is the stated location in China. Consequently, the public profile of PT_Moisha remains limited to the single reported ransomware event and the associated TTPs that were explicitly mentioned.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB