Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

In a campaign that began around autumn 2017, the threat actor known as LuckyMouse compromised a Mongolian national data center and used access to government web infrastructure to redirect site visitors toward attacker-controlled resources. The incident was more than a website defacement: one intrusion into shared hosting created a route to alter multiple official websites. Kaspersky reported the technical findings in June 2018; the public record does not establish how many sites were affected or whether visitors’ devices were successfully infected.

What happened in the Mongolia campaign?

Kaspersky detected the campaign in March 2018 and assessed that it had likely been active since autumn 2017. Its investigation found a compromised national data center, HyperBro remote-access malware on systems there, and malicious JavaScript injected into government websites. The scripts redirected visitors to infrastructure associated with exploit and surveillance frameworks.

The sequence, as described in Kaspersky’s technical account, was:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Attackers gained access to people or systems associated with the national data center. The precise entry route is not publicly established.
  2. They expanded their foothold within the data-center environment and installed HyperBro on some systems.
  3. They altered selected official websites hosted through or connected to that environment.
  4. Injected JavaScript sent visitors to attacker-controlled infrastructure, potentially exposing them to further targeting.

This is a watering-hole technique: compromise a site its intended audience trusts, then use that site to draw visitors toward malicious content. The evidence supports website tampering and redirection; it does not show that every government site was affected, that the sites were defaced or taken offline, or that all redirected visitors became infected. Kaspersky’s technical report is the primary public account of the malware and attack mechanics.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

How the incident unfolded

When What is reported
Autumn 2017 Kaspersky believes the campaign became active.
Mid-November 2017 Kaspersky observed traces of HyperBro in the data center.
December 2017–January 2018 Timestamps associated with campaign modules fell in this period.
Late 2017 Government websites were redirecting visitors to malicious infrastructure.
March 2018 Kaspersky detected the ongoing campaign.
June 13, 2018 Kaspersky published its technical report.
June 15, 2018 CyberScoop published reporting identifying Mongolia and adding geopolitical context.

Kaspersky’s public report described the victim as a Central Asian country. CyberScoop identified the country as Mongolia, relying in part on an anonymous source familiar with the report. That distinction matters: Mongolia is the identification in subsequent reporting, while Kaspersky’s published technical account used broader geographic wording.

Why compromising the data center mattered

A national data center can host or support services for multiple public agencies. An attacker who reaches that shared layer may be able to affect several resources without independently breaking into each agency’s website. That is the incident’s central security lesson: consolidation can simplify government IT operations, but it also concentrates risk and can magnify the impact of a single compromise.

  • Direct website compromise: an attacker changes a particular site or its content-management system.
  • Hosting-layer compromise: an attacker gains access to infrastructure that supports multiple sites or services.
  • Watering-hole use: a legitimate site is altered to redirect or expose its visitors to attacker-controlled resources.
  • Visitor infection: a device executes malicious code or is otherwise compromised. Redirection creates exposure, but the public reporting does not confirm the scale of successful infections.
  • Data theft: information is copied out of government systems. HyperBro could support theft, but the cited accounts do not document a specific cache of stolen Mongolian data.

The available accounts support infrastructure compromise, website alteration, and redirection. They do not establish the full extent of data theft from Mongolian government systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Who was LuckyMouse?

Kaspersky attributed the campaign to LuckyMouse, a threat actor also tracked by some security researchers as APT27 or EmissaryPanda. CyberScoop also noted IronPanda as an associated name. Vendor naming conventions are not perfectly uniform, so these labels should be treated as overlapping industry tracking names, not as proof that every report using one name describes precisely the same set of operations.

Kaspersky linked the campaign to a Chinese-speaking actor based on tools, tactics, infrastructure, and previous use of the command-and-control domain update.iaacstudio[.]com. That technical attribution is not, by itself, public proof of direct Chinese government tasking. The Council on Foreign Relations lists China as the suspected state sponsor and classifies the incident as espionage; it does not make that sponsorship an established legal or official finding. CFR’s incident entry also records the Mongolian government’s reaction as unknown.

What malware and infrastructure were involved?

HyperBro on data-center systems

Kaspersky described HyperBro as a final-stage, in-memory remote administration tool. It gave operators remote control over compromised systems and could support information manipulation or theft. Traces appeared in the data center from mid-November 2017. HyperBro was found on systems in the data-center environment; the reporting does not establish that it was the payload delivered directly to every website visitor.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Injected scripts and visitor redirection

Kaspersky linked the redirects to infrastructure associated with ScanBox and BeEF, frameworks used to collect information about visitors or support further targeting. Its report documented these historical, defanged URL artifacts:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • google-updata[.]tk:443/hook.js
  • windows-updata[.]tk:443/scanv1.8/i/?1

These are forensic indicators from the 2017–2018 campaign, not live destinations to visit.

A malware loading chain

Kaspersky described a chain that used a legitimate Symantec pcAnywhere executable to side-load a launcher DLL. A decompressor unpacked the final payload, which used Metasploit’s shikata_ga_nai encoder and LZNT1 compression before being injected into the memory of svchost.exe. In practical terms, the chain attempted to make malicious code harder to inspect and run it inside a process that is ordinarily present on Windows systems.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Infrastructure used to obscure the operators

A primary command-and-control domain resolved to an IP address associated with a Ukrainian ISP and a MikroTik router running firmware version 6.34.4, dated March 2016, with SMBv1 enabled. Kaspersky suspected that the router had itself been compromised and used as a relay for malware traffic. Its location is not evidence of Ukrainian involvement; the account describes it as intermediary infrastructure.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known—and what remains uncertain

The public record is strongest on technical observations made by Kaspersky and more limited on the campaign’s total impact. Neither the available reporting nor CFR’s tracker supplies a complete victim count or a public account of government remediation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Not established: the number of affected websites, the full list of agencies, or how many visitors were exposed.
  • Not established: the number of visitors whose devices were successfully compromised, or the volume and type of data exfiltrated.
  • Unclear: the initial access route. Kaspersky discussed spear-phishing and watering holes among possibilities in the actor’s broader activity but could not prove which method was used here.
  • Not proven for this campaign: use of the CVE-2017-11882 Microsoft Office Equation Editor exploit. Kaspersky cautioned that it could not confirm that exploit was involved in this intrusion.
  • Not established: direct Chinese government orders, lasting damage, or a specific political or disruptive objective.
  • Unknown in CFR’s tracker: the Mongolian government’s response.

The evidence is consistent with espionage: the target was government infrastructure, the attackers deployed a remote-access tool, manipulated trusted websites, and used infrastructure that could conceal their location. CFR classifies the incident as espionage. Public reporting does not identify particular documents stolen, decisions influenced, or individuals confirmed as victims.

What public-sector operators can learn from it

The following are defensive lessons drawn from the attack mechanics, not controls that the cited reports say Mongolia had or lacked:

  • Segment shared hosting: separate public web services, administrative access, and core data-center management so a web-layer foothold cannot automatically reach the broader environment.
  • Separate credentials and privileges: avoid reusing website-management credentials for infrastructure administration; limit and monitor privileged accounts.
  • Monitor web integrity: alert on unexpected JavaScript changes, unfamiliar external scripts, and redirects from official sites.
  • Treat public websites as part of the security perimeter: trusted agency domains can become a delivery path to the public if their content or hosting is compromised.
  • Harden network appliances: patch routers and other infrastructure, disable obsolete protocols such as SMBv1 where operationally possible, and check for unexpected management exposure.
  • Watch for stealthy execution: investigate in-memory activity, DLL side-loading, and abnormal behavior by legitimate signed software rather than relying only on file-based malware detection.
  • Plan for cross-agency response: shared services need an incident plan that coordinates containment, evidence preservation, and communication across every dependent agency.
  • Retain useful telemetry: preserve web-server, identity, endpoint, DNS, and network logs so investigators can correlate activity across a shared environment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.