Teleboyi

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:20:29

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Teleboyi is a threat actor reportedly based in China, associated with the PlugX RAT. TeamT5 identified a custom PlugX loader used by Teleboyi that employs a similar string decryption algorithm as seen in the McUtil.dll loader from Operation Harvest. While there are weak links to the dsqurey[.]com domain, the connection remains uncertain due to the domain's registration history.

Reports & references

  • Trend Micro — Updated Shadowpad Malware Leads To Ransomware Deployment (report)

External references