Skip to content

Threat actor

COSEINC

Last fetched

COSEINC is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Founded by former Cyber Security Agency (CSA) official Thomas Lim, the Computer Security Initiative Consultancy (COSEINC) is a Singapore-based cybersecurity firm with extensive spyware and surveillance operations. In November 2021, it was blacklisting by the U.S. Department of Commerce, which cited the company's misuse of cyber tools to gain unauthorized access to information systems. Lim is known for organizing the SyScan security conference, which was sold to the Chinese technology firm Qihoo 360, another sanctioned entity by the U.S. Lim also operates Pwnzen Technology, a Singaporean subsidiary of China's Shanghai Ben Zhong Information Technology (Pwnzen InfoTech). Founded in 2014 by Chinese hackers associated with the Pangu Team, Pwnzen specializes in cyber monitoring and defense on behalf of China's government. The company collaborates closely with Chinese cyber institutions like CNCERT and CNNVD, which is linked to China's Ministry of State Security. Pwnzen is involved in hacking the phone of a Chinese opposition figure to access their social media accounts.

Techniques by tactic

No ATT&CK techniques are recorded for COSEINC in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to COSEINC today — this states the absence of a published link, not that COSEINC has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from COSEINC into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.