IronHusky

First seen
2017-07-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:07:17

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:ru country_code:mn

Context

IronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research institutes. Since their initial attacks ceased in 2018, they have been working on a new remote access trojan dubbed MysterySnail.

Reports & references

  • Kaspersky — 104509 (report)
  • supportcenter.checkpoint.com — Portal (report)

External references