The operation targeted governments, NGOs and think tanks in Asia, Europe and the United States. Malware typical of China-aligned actors, such as ShadowPad and Spyder, was employed. ESET confirms that the responsible group is FishMonger, operated by the contracting company I-SOON
The United States Department of Justice (DOJ) recently made public an indictment against employees of the Chinese contracting company I-SOON, accused of participating in several global espionage operations. These include attacks already documented by researchers at ESET, a global European leader in the cybersecurity market, within its Threat Intelligence reports and attributed to the FishMonger group, the operating arm of I-SOON. One such incident involves seven organizations targeted in 2022 as part of a campaign ESET has dubbed Operation FishMedley. In parallel with the release of the indictment, the FBI — which refers to the group as Aquatic Panda — placed those involved on its most wanted list. Several attacks described in the indictment match those already reported by ESET in an APT report published in early 2023. With the new update, ESET is now sharing technical information about this espionage campaign targeting governments, NGOs and research centers in Asia, Europe and the United States.
"Over the course of 2022, we investigated several compromises involving malware such as ShadowPad and SodaMaster, frequently used by groups aligned with China. We managed to bring seven separate incidents under a single operation, what we called FishMedley," explains Matthieu Faou, ESET researcher who analyzed Operation FishMonger. “During the investigation, we were able to independently confirm that FishMonger is an espionage group operated by I-SOON, a Chengdu-based contracting company, which was already at the center of a significant document leak in 2024,” adds Faou.
During Operation FishMedley, conducted in 2022, FishMonger targeted government entities in Taiwan and Thailand, Catholic organizations in Hungary and the United States, a US NGO, a geopolitical think tank in France, and an unidentified organization in Turkey. Although the sectors and countries involved are heterogeneous, most of the targets appear consistent with the strategic interests of the Chinese government.
In most cases, the attackers had privileged access to local networks, including domain administrator credentials. The malware used includes ShadowPad, SodaMaster and Spyder, tools commonly used by actors linked to China. In addition to these, FishMonger used a custom password exfiltration tool, a tool for interacting with Dropbox (probably for transferring exfiltrated data), the fscan network scanner, and a NetBIOS scanner.
FishMonger, a group managed by the Chinese contractor I-SOON, is associated with the Winnti Group and in all likelihood operates from the city of Chengdu, where the I-SOON office is still located. The group is also known by other names, including Earth Lusca, TAG 22, Aquatic Panda and Red Dev 10. ESET had already published an analysis on FishMonger in early 2020, on the occasion of targeted attacks against universities in Hong Kong during the civil society mobilisations that began in 2019. The group is also known for using watering hole attacks. Its set of used tools includes, in addition to ShadowPad and Spyder, also Cobalt Strike, FunnySwitch, SprySOCKS and the BIOPASS RAT backdoor.
For a detailed technical analysis of the FishMedley operation and the tools used by the FishMonger group, you can consult the post “Operation FishMedley” published by ESET Research on WeLiveSecurity.com. To stay updated on the latest research, you can follow ESET Research on Twitter (now X).






