Marko Polo is a Russian-speaking cybercrime group associated with cryptocurrency fraud and malware distribution operations. It has been linked to traffer-style activity that uses social engineering, compromised websites, and shared criminal infrastructure to direct victims toward credential theft, wallet theft, and infostealer infections. The group is known in reporting under the aliases Marko Polo, markopolo, and marko_polo. Marko Polo has been associated with sub-teams including Slavic Nation Empire, also referenced as SNE and Slavice Nation Land. These sub-teams have been tied to ClickFix-style campaigns that impersonate legitimate services such as Google Meet and other popular online platforms in order to trick users into manually executing malicious commands. In these operations, victims are lured through fake error messages, verification prompts, or meeting invitations, after which malware is delivered to Windows and macOS systems. Malware families observed in activity linked to Marko Polo-associated sub-teams include StealC, Rhadamanthys, and Atomic macOS Stealer. The group operates within the broader Russian-speaking cybercrime ecosystem and has been discussed alongside other traffer and scam groups such as CryptoLove, CrazyEvil, and Wagmi. Reporting indicates that Marko Polo-linked operations may rely on shared templates, common distribution infrastructure, and possibly third-party services that manage traffic distribution or campaign enablement for multiple criminal teams. This reflects an industrialized cybercrime model in which specialized actors handle lures, victim acquisition, and malware delivery on behalf of scam or theft-focused crews. Tradecraft associated with Marko Polo includes impersonation of trusted brands and services, use of compromised WordPress sites and social media pages as delivery infrastructure, and abuse of user-driven execution flows to bypass browser and endpoint protections. The group’s campaigns have targeted both consumers and enterprises, including users of collaboration platforms, software services, and cryptocurrency-related ecosystems. Its activity is consistent with financially motivated operations focused on scalable victim acquisition, credential compromise, infostealer deployment, and downstream fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a trafficker team using more traditional malware-based approaches (contrast point to Rublevka Team’s JavaScript-based draining).
Named as a traffer group potentially linked via shared infrastructure to a broader crypto-theft/social-engineering ecosystem.
markopolo is a cybercrime group whose sub-team Slavic Nation Empire is involved in the ClickFix campaign, leveraging fake Google Meet and other service pages to deliver infostealers to Windows and macOS users.
Marko Polo is a Russian-speaking cybercrime group involved in cryptocurrency scams and information-stealing malware campaigns. They use the ClickFix social engineering tactic to deliver infostealers to users by impersonating services like Google Meet.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.