Elusive Comet is a financially motivated threat actor focused on stealing cryptocurrency through highly tailored social-engineering operations against members of the crypto ecosystem. The actor has been associated with a fraudulent venture-capital front, Aureon Capital, used to build credibility with targets and lure them into malware infection workflows. Reported targeting has centered on crypto experts and related professionals. The group’s tradecraft includes sophisticated impersonation and social engineering, including fake interview or meeting scenarios conducted over videoconferencing platforms to persuade victims to execute malicious components or grant remote access. These operations are designed to establish initial access, deploy malware, and conduct post-compromise theft of digital assets. Public reporting has also noted evidence pointing to North Korean involvement, aligning the actor with the broader pattern of DPRK-linked financially motivated operations against cryptocurrency holders, platforms, and specialists. Elusive Comet is notable for combining convincing business pretexts, spoofed organizational identity, and malware-enabled theft to monetize intrusions directly through crypto theft rather than conventional ransomware or data-extortion activity. No distinct sub-groups are established in the available high-confidence reporting beyond the Aureon Capital front identity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor using social engineering and malware to target cryptocurrency experts and steal funds.
Elusive Comet is a threat actor using fake business meetings and social engineering to gain remote access via Zoom, install malware, and steal cryptocurrency, with evidence suggesting North Korean involvement.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.