Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:44:55 UTC Home > List all groups > List all tools > List all groups using tool HenBox Tool: HenBox Names HenBox Category Malware Type Info stealer Description (Palo Alto) Once installed, HenBox steals information from the devices from a myriad of sources, including many mainstream chat, communication, and social media apps. The stolen information includes personal and device information. Of note, in addition to tracking the compromised device’s location, HenBox also harvests all outgoing phone numbers with an “86” prefix, which is the country code for the People’s Republic of China (PRC). It can also access the phone’s cameras and microphone. Information MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 30 December 2022 Download this tool card in JSON format All groups using tool HenBox Changed Name Country Observed APT groups Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon 2010-Oct 2024 Mustang Panda, Bronze President 2012-Jun 2025 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b6b1e735-2a78-4f98-8baa-ce740cad84ea Page 1 of 2 2 groups listed (2 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b6b1e735-2a78-4f98-8baa-ce740cad84ea https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b6b1e735-2a78-4f98-8baa-ce740cad84ea Page 2 of 2