CSIDB logo
Incident

China Aoyuan Group

Incident posture

Attack window
Sep 2022
Location
Hong Kong
Status
Historical
CIA posture
Available to members
Updated
2025-10-16 00:00

Linked entities

Victim
China Aoyuan Group
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Aoyuan Healthy Life Group, a subsidiary of China Aoyuan Group with operations across Hong Kong, Australia, and Canada, suffered a ransomware attack by the PT_Moisha group. The attackers claimed to have exfiltrated 200 GB of documents, providing a 200 MB sample as proof, while asserting their status as an established threat actor despite being newly identified. The breach impacted the publicly listed company's data security, though specific operational disruptions or ransom demands were not detailed in available reports.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around September 28, 2022, the PT_Moisha ransomware group publicly claimed responsibility for a cyberattack targeting Aoyuan Healthy Life Group, a subsidiary of China Aoyuan Group. The Hong Kong-based victim entity maintained operational offices in Sydney, Toronto, and Vancouver, forming part of a larger Chinese conglomerate founded in 1996 and listed on the Hong Kong Stock Exchange since 2007. PT_Moisha, identifying itself as an established group despite being newly recognized by researchers, infiltrated Aoyuan Healthy Life Group’s computer networks and exfiltrated approximately 200 gigabytes of documents. The attackers established contact with cybersecurity researchers via the qTox encrypted messaging platform to disclose their involvement.

PT_Moisha provided researchers with a 90-file sample totaling 200 megabytes as proof of the compromise, representing a fraction of the stolen data. The exfiltrated documents reportedly included corporate records, though specific file types or sensitive data categories were not detailed in the disclosed sample. The ransomware group maintained possession of the full 200 GB dataset at the time of disclosure, implying ongoing leverage for potential extortion or secondary distribution. No explicit ransom demands or payment conditions were referenced in the initial outreach. China Aoyuan Group’s corporate structure, including its Cayman Islands registration, was highlighted in connection with the incident, though the breach appeared confined to the Healthy Life Group subsidiary. The attack’s operational impacts—including potential disruptions to business functions, financial losses, or containment measures—were not described in available disclosures.

Sources

Sources available to members: 1 source.

CSIDB