MB-0001 MB-0002 MB-0003 MB-0004 MB-0005 MB-0006
MB-0007
MB-0008
MB-0009 MB-0010
MALWAREBOX / THREAT ACTORS

Actor registry

One dossier per actor with an assigned Malwarebox ID. Open a dossier for the profile, our analyses and the linked IIM Chains. The sequence at the left edge is the index: eight assigned, two reserved.

ORIGIN
All8 Russia2 Iran1 North Korea1 Unattributed4
8 actors
IIM FEED 40 chains 6 mapped to 5 of these actors 24 techniques updated 30 Aug 2026 Open feed
MB-0001 Gamaredon ๐Ÿ‡ท๐Ÿ‡บ Russia โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine Longest continuous tracking history in the program. Infrastructure rotations followed across seven analyses. 7analyses 2IIM chains 2013 โ€“ present
MB-0002 APT28 ๐Ÿ‡ท๐Ÿ‡บ Russia โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine, NATO/EU Geofencing used as a targeting signal rather than an evasion measure, observed in the CVE-2026-21509 chain. 1analyses 1IIM chains 2004 โ€“ present
MB-0003 MuddyWater ๐Ÿ‡ฎ๐Ÿ‡ท Iran โ†’ ๐Ÿ‡ฎ๐Ÿ‡ถ๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ฏ๐Ÿ‡ด๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡ธ Telegram bot naming patterns, RustyStealer compiler fingerprinting and the build system itself used as an indicator. 3analyses 2IIM chains 2017 โ€“ present
MB-0004 UAC-0226 Unknown โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine WinRAR alternate data streams into reflective GIFTEDCROOK loading, followed across two analyses. In public IIM feed 2analyses 1IIM chains 2025 โ€“ present
MB-0005 UAC-0184 Unknown โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine OneDrive sideload to Remcos, then a signed network stack that removes the unsigned-binary signal. 2analyses 1IIM chains 2023 โ€“ present
MB-0006 UAC-0244 / UAC-0247 Unknown โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine Malware targeting FPV drone operators through trojanised ground-station tooling. 1analyses 1IIM chains 2026 โ€“ present
MB-0009 GhostShell Unknown โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine (UAV / defense supply chain) Own EC-P-256 mTLS implant with per-implant client certificates, Telegram dead-drop stager, Vidar v2 over Xray/VLESS/REALITY. Externally cited 1analyses 2IIM chains 2026 โ€“ present
MB-0010 APT43 ๐Ÿ‡ฐ๐Ÿ‡ต North Korea โ†’ ๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ช๐Ÿ‡บ CHM tradecraft: compiled help files as a delivery format that still passes most mail filters. 1analyses 1IIM chains 2012 โ€“ present
DOSSIERMB-0001

Gamaredon

๐Ÿ‡ท๐Ÿ‡บ Russia โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine

Gamaredon operates at a tempo that makes infrastructure the most reliable pivot: domains rotate faster than payloads change. We track the actor through dynamic DNS clusters and geofenced delivery, which restricts second-stage payloads to Ukrainian egress ranges. Each rotation window is documented with the Kraken query used to detect it, so the method is reproducible against later rotations.

ALIASES
Armageddon, Shuckworm, Primitive Bear
ACTIVE
2013 โ€“ present
TOOLING
PteroGraphin, PteroLoad, custom VBScript droppers
ASSESSMENT
High confidence, sustained tracking
IIM TECHNIQUE TAGS
IIM-T019 Geofenced Delivery IIM-T024 Archive Container IIM-T021 IIM-T008 Dynamic DNS Abuse IIM-T011 IIM-T013
MALWAREBOX ANALYSES
7
Following Gamaredons Infrastructure Rotations using Kraken (1/7) 23 Mar 2026
Part 1 of 7 of building the Malwarebox EcosystemOfficial Website: https://kraken.malwarebox.eu Whitepaper Tracking... The post Following Gamaredons Infrastructure Rotations using Kraken...
Gamaredon: Now Downloading via Windows Updates Best Friend โ€œBITSโ€ 13 Jan 2026
Thereโ€™s yet another update in Gamaredons GamaLoad scripts, which pushed me to... The post Gamaredon: Now Downloading via Windows Updates Best Friend โ€œBITSโ€ appeared first on Synaptic...
Defending Against Gamaredon: Practical Controls That Actually Work 06 Jan 2026
EDIT: If youโ€™re interested in how I efficiently track threat actors such... The post Defending Against Gamaredon: Practical Controls That Actually Work appeared first on Synaptic Security Blog .
Gamaredon: Same Goal, Fewer Fingerprints 05 Jan 2026
In malware analysis, it is tempting to describe change as innovation.New tricks,... The post Gamaredon: Same Goal, Fewer Fingerprints appeared first on Synaptic Security Blog .
GamaWiper Explained: Gamaredonโ€™s โ€œNewโ€ Anti-Analysis Weapon 22 Dec 2025
After my recent blog posts covering Gamaredonโ€™s ongoing PterodoGraph campaign targeting Ukraine,... The post GamaWiper Explained: Gamaredonโ€™s โ€œNewโ€ Anti-Analysis Weapon appeared first on...
Inside Gamaredon 2025: Zero-Click Espionage at Scale 22 Nov 2025
UPDATE 22.12.2025: Gamaredon updated itโ€™s payload delivery infrastructure. You can find more... The post Inside Gamaredon 2025: Zero-Click Espionage at Scale appeared first on Synaptic...
How a Russian Threat Actor Uses a Recent WinRAR Vulnerability in Their Ukraine Operations 13 Nov 2025
If youโ€™re interested in reading more about Gamaredon check out my other... The post How a Russian Threat Actor Uses a Recent WinRAR Vulnerability in Their Ukraine Operations appeared...
IIM CHAINS
2
confirmed

IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTAโ€ฆ

entry stagingร—4 redirectorร—6 c2 payloadร—2 c2ร—2
16 entities 18 relations 9 techniques observed 03 Jun 2026
confirmed in review

IIM chain for the November 2025 Gamaredon zero-click delivery path: a Ukraine-themed RAR archive abuses CVE-2025-6218/CVE-2025-8088 style archive delivery to place an HTA in the Windows Startup folder. The HTA/loader reaches DynDNS-backed deliveryโ€ฆ

entryร—2 stagingร—2 payload redirectorร—4 staging redirector c2ร—2
13 entities 13 relations 12 techniques observed 11 Nov 2025
DOSSIERMB-0002

APT28

๐Ÿ‡ท๐Ÿ‡บ Russia โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine, NATO/EU

A single campaign entry, kept because the geofencing behaviour is instructive: the delivery filter is narrow enough that the allowed ranges themselves describe the target set. The analysis reconstructs the filter from collected samples and shows how the same signal can be queried across unrelated actors.

ALIASES
Fancy Bear, Sofacy, Forest Blizzard
ACTIVE
2004 โ€“ present
TOOLING
CVE-2026-21509 exploit chain, HeadLace-style loaders
ASSESSMENT
Moderate confidence, single campaign
IIM TECHNIQUE TAGS
IIM-T004 Exploit Delivery IIM-T019 Geofenced Delivery
MALWAREBOX ANALYSES
1
APT28: Geofencing as a Targeting Signal (CVE-2026-21509 Campaign) 03 Feb 2026
EDIT: 04.02.2026: I have YARA Rules available for detection, contact me at... The post APT28: Geofencing as a Targeting Signal (CVE-2026-21509 Campaign) appeared first on Synaptic Security Blog .
IIM CHAINS
1
IIM-C-0102 Exploit document to loader
T004 Exploit Delivery โ†’ T019 Geofenced Delivery โ†’ T031 Reflective Load
DOSSIERMB-0003

MuddyWater

๐Ÿ‡ฎ๐Ÿ‡ท Iran โ†’ ๐Ÿ‡ฎ๐Ÿ‡ถ๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ฏ๐Ÿ‡ด๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡ธ

The interesting artefact here is not the malware but the workshop around it. Compiler fingerprints, path fragments and a recurring build identity ("Jacob") link samples that share no network infrastructure. Telegram bot naming follows a scheme regular enough to enumerate, which gives an early-warning signal ahead of campaign delivery.

ALIASES
Static Kitten, Mango Sandstorm, Seedworm
ACTIVE
2017 โ€“ present
TOOLING
RustyStealer, Telegram bot C2, custom build system
ASSESSMENT
High confidence on tooling, medium on scope
IIM TECHNIQUE TAGS
IIM-T042 Legit Service C2 IIM-T055 Toolchain Fingerprint IIM-T061
MALWAREBOX ANALYSES
3
Observed Telegram Bot Naming Patterns in Recent MuddyWater Malware Activity 21 Mar 2026
I recently took a look at the wave of MuddyWater malware samples... The post Observed Telegram Bot Naming Patterns in Recent MuddyWater Malware Activity appeared first on Synaptic Security Blog .
RustyStealer: Your Compiler Is Snitching on You 15 Jan 2026
As already mentioned in my last MuddyWater article, I originally planned to... The post RustyStealer: Your Compiler Is Snitching on You appeared first on Synaptic Security Blog .
MuddyWater: When Your Build System Becomes an IOC โ€“ โ€œJacobโ€ 10 Jan 2026
EDIT 2026-01-18: I published a follow-up article analyzing the evolution and version... The post MuddyWater: When Your Build System Becomes an IOC โ€“ โ€œJacobโ€ appeared first on Synaptic...
IIM CHAINS
2
IIM-C-0088 Telegram dead-drop C2
T042 Legit Service C2 โ†’ T013 Beacon Interval Jitter
IIM-C-0093 Rust stealer build lineage
T055 Toolchain Fingerprint โ†’ T061 Credential Collection
DOSSIERMB-0004

UAC-0226

Unknown โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine
In public IIM feed

Delivery hides the payload in alternate data streams of an archive, which survives most inspection paths that only read the primary stream. The follow-up tracks how the loader changed after the technique was published, which is the more useful half: it shows what the actor kept when the cheap part stopped working.

ALIASES
None assigned
ACTIVE
2025 โ€“ present
TOOLING
GIFTEDCROOK, WinRAR ADS obfuscation
ASSESSMENT
Attribution open, tooling confirmed
IIM TECHNIQUE TAGS
IIM-T024 Archive Container IIM-T027 Alternate Data Stream IIM-T031
MALWAREBOX ANALYSES
2
Tracking UAC-0226 Tooling Evolution: From WinRAR ADS to Reflective GIFTEDCROOK Loading 24 Jun 2026
A few months ago, I analyzed a UAC-0226 campaign delivering a GIFTEDCROOK... The post Tracking UAC-0226 Tooling Evolution: From WinRAR ADS to Reflective GIFTEDCROOK Loading appeared...
Obfuscation Without Effort: Breaking a UAC-0226 GIFTEDCROOK Stealer 09 Apr 2026
EDIT: I have YARA rules available for this one, if you need... The post Obfuscation Without Effort: Breaking a UAC-0226 GIFTEDCROOK Stealer appeared first on Synaptic Security Blog .
IIM CHAINS
1
confirmed in review

Ukraine-focused chain reconstructed from submitted artifacts and static analysis. The archive container itself was not submitted, so archive-level hash and original email metadata remain unavailable. The member names and dropped artifacts are consistent withโ€ฆ

entry stagingร—3 payloadร—2 c2ร—3
9 entities 11 relations 1 techniques observed 28 May 2026
DOSSIERMB-0005

UAC-0184

Unknown โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine

Two analyses covering one shift in tradecraft. The first documents a OneDrive-hosted sideload chain ending in Remcos. The second covers the move to signed network components, which quietly retires the detection most defenders were relying on and forces the pivot back onto behaviour.

ALIASES
None assigned
ACTIVE
2023 โ€“ present
TOOLING
Remcos RAT, signed network components
ASSESSMENT
Attribution open
IIM TECHNIQUE TAGS
IIM-T034 DLL Sideload IIM-T038 Code Signing Abuse IIM-T042
MALWAREBOX ANALYSES
2
UAC-0184 Tooling Evolution: OneDrive Sideload to Remcos 27 Jun 2026
Malware: HijackLoader / IDATLoader -> Remcos Agent 7.1.0 ProActor tracking: UAC-0184 /... The post UAC-0184 Tooling Evolution: OneDrive Sideload to Remcos appeared first on Synaptic...
UAC-0184: From HTA to a Signed Network Stack 18 May 2026
EDIT: The next article in my UAC series is out: https://blog.synapticsystems.de/uac-0247-malware-targeting-fpv-operators/ Actor:... The post UAC-0184: From HTA to a Signed Network Stack...
IIM CHAINS
1
confirmed in review

Observed UAC-0184 chain from gated HTA and ZIP delivery into Plane9-based sideloading, encoded local blobs, pseudo-PNG IDAT staging, LZNT1 unpacking and a signed VSLauncher / PassMark network-capable payload bundle. The internal controller or C2 elementโ€ฆ

entryร—2 stagingร—8 payloadร—3 c2ร—2
15 entities 20 relations 5 techniques
DOSSIERMB-0006

UAC-0244 / UAC-0247

Unknown โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine

Two designations are tracked under one Malwarebox ID because the sample overlap is not yet separable. Delivery targets the operator workstation rather than the aircraft: trojanised configuration and firmware tooling distributed inside operator communities.

ALIASES
Clustered pair, separation unresolved
ACTIVE
2026 โ€“ present
TOOLING
FPV toolchain trojans, ground-station installers
ASSESSMENT
Cluster overlap unresolved
IIM TECHNIQUE TAGS
IIM-T017 Supply Chain Insert IIM-T070
MALWAREBOX ANALYSES
1
UAC-0244 / UAC-0247: Malware Targeting FPV drone operators 21 May 2026
Surprise, surprise โ€“ a new UAC article ๐Ÿ˜ Actor: UAC-0244 / UAC-0247... The post UAC-0244 / UAC-0247: Malware Targeting FPV drone operators appeared first on Synaptic Security Blog .
IIM CHAINS
1
confirmed

Campaign chain for a Ukraine-focused lure targeting FPV/UAV-related audiences. The flow starts with a humanitarian-aid themed archive/LNK and HTA delivery layer on ukrvarta.online, moves through external JavaScript and updater.txt payload staging, persists asโ€ฆ

entryร—2 stagingร—3 payloadร—2 staging redirector payloadร—4 c2
14 entities 13 relations 5 techniques observed 24 Mar 2026
DOSSIERMB-0009

GhostShell

Unknown โ†’ ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine (UAV / defense supply chain)
Externally cited

The most self-built toolset in the registry. Each implant carries its own client certificate, so mutual TLS doubles as an access-control list and sinkholing needs the private key. The stager reads tasking from a Telegram dead drop and Vidar v2 arrives over a REALITY transport that mimics benign TLS. Tracked after publication by Zscaler ThreatLabz and the Belgian CCB.

ALIASES
Malwarebox-assigned name
ACTIVE
2026 โ€“ present
TOOLING
EC-P-256 mTLS implant, Telegram dead drop, Vidar v2
ASSESSMENT
Confirmed, externally corroborated
IIM TECHNIQUE TAGS
IIM-T045 Mutual TLS C2 IIM-T049 Certificate Pinning IIM-T042
MALWAREBOX ANALYSES
1
GhostShell (MB-0009): Targeting Ukraineโ€™s UAV Operations and Defense Supply Chain 22 Jun 2026
Today, we are taking a look at malware linked to yet another... The post GhostShell (MB-0009): Targeting Ukraineโ€™s UAV Operations and Defense Supply Chain appeared first on Synaptic...
IIM CHAINS
2
IIM-C-0148 Per-implant mTLS C2
T045 Mutual TLS C2 โ†’ T049 Certificate Pinning
IIM-C-0150 Dead-drop tasking
T042 Legit Service C2 โ†’ T021 Script Stager โ†’ T061 Credential Collection
DOSSIERMB-0010

APT43

๐Ÿ‡ฐ๐Ÿ‡ต North Korea โ†’ ๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ช๐Ÿ‡บ

CHM remains in use because it survives filtering that blocks macros and script attachments outright. The analysis walks the compiled help file end to end, from the embedded shortcut object to the PowerShell recon stage and gives the extraction steps needed to compare CHM samples at volume.

ALIASES
Kimsuky, Emerald Sleet, Thallium
ACTIVE
2012 โ€“ present
TOOLING
CHM help files, PowerShell recon stagers
ASSESSMENT
High confidence
IIM TECHNIQUE TAGS
IIM-T011 LNK Execution IIM-T021 Script Stager IIM-T058
MALWAREBOX ANALYSES
1
Inside Kimsukyโ€™s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery 29 Jun 2026
Actor tracking: APT43 (Kimsuky) / MB-0010 I canโ€™t sleep right now, because itโ€™s... The post Inside Kimsukyโ€™s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery appeared...
IIM CHAINS
1
confirmed

ENKI-attributed Kimsuky lane. Fake Webex page based on a legitimate meeting schedule downloads an ALZip archive containing fix-camera.jse, which drops meeting.html and mTSTCv8.mdxm/loadDll.dll. The downloader retrieves engine.dat/spyInster.dll, which installsโ€ฆ

entry stagingร—2 redirector stagingร—2 payloadร—3 c2 staging
11 entities 13 relations 2 techniques observed 30 Apr 2026