CardinalLizard
- First seen
- 2018-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:13:37
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:hk country_code:jp country_code:kr country_code:tw
Context
CardinalLizard, a cyber threat actor linked to China, has targeted entities in Asia since 2018. Their methods include spear-phishing, custom malware with anti-detection features, and potentially shared infrastructure with other actors.
Reports & references
- Kaspersky — 89117 (report)