MoYu Group
Also known as BADBOX
Reports
3
First seen
Aug 21, 2026
Last seen
Aug 24, 2026
Motivation
Financial
Targeting
Sectors
Victim regions
China ×1
Top ATT&CK techniques
T1071.001 Application Layer Protocol: Web Protocols ×3T1105 Ingress Tool Transfer ×3T1195 Supply Chain Compromise ×3T1041 Exfiltration Over C2 Channel ×2T1090 Proxy ×1T1059.001 Command and Scripting Interpreter: PowerShell ×1T1059 Command and Scripting Interpreter ×1T1082 System Information Discovery ×1T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage ×1
Indicators
hash_md5 ×27domain ×10url ×5ip_v4 ×4
Indicator values are available on Pro and via the API.