CoralRaider is a cybercrime threat actor associated with global malware distribution and credential-stealing activity. The group has been observed delivering multiple commodity malware families, including Lumma, Rhadamanthys, Cryptbot, Quasar RAT, and Amadey, and appears to operate as a flexible malware delivery and access-enablement actor rather than a ransomware operator. Reporting links CoralRaider to campaigns that use multi-stage infection chains beginning with shortcut-file lures and progressing through script-based loaders and staged payload retrieval to install follow-on malware. CoralRaider has used delivery chains involving malicious LNK files, mshta-launched HTA payloads, obfuscated PowerShell, compressed intermediate stages, scheduled-task persistence, and final payload deployment. The actor has also been associated with CDN-backed malware distribution and with the use of FTP-based infrastructure for discreet payload transfer. Observed tradecraft indicates emphasis on defense evasion, layered staging, and operational flexibility through shifting infrastructure patterns. One reported campaign used a mixed domain strategy spanning Portuguese and Russian infrastructure, while other reporting noted earlier Vietnamese-linked infrastructure, suggesting deliberate efforts to complicate attribution and reduce detection. The group’s activity is consistent with financially motivated cybercrime focused on credential theft and broader post-compromise monetization. CoralRaider has been specifically identified as distributing Lumma infostealer worldwide, including against entities in Germany and Poland. Known aliases are limited, and CoralRaider is the primary name in common use.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
591 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prominent threat actor group that has used the Lumma infostealer.
CoralRaider is a cybercrime group distributing info-stealing malware globally, targeting credentials, financial data, and social media accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.