WildPressure is a cyber-espionage activity cluster publicly identified in 2020 and associated with targeting of industrial-related entities in the Middle East. The operation has been linked to deployment of the Milum remote-control Trojan, described as a mature C++ backdoor using victim-specific RC4 keys. Reported victimology indicates a focus on industrial organizations rather than broad opportunistic targeting, consistent with a selective intelligence-collection mission. Available reporting supports espionage-oriented post-compromise activity and remote control of infected systems, but does not provide high-confidence evidence for ransomware, destructive operations, or financially motivated crime. WildPressure is best tracked as a distinct Middle East-focused intrusion set with limited publicly corroborated detail on its operators, infrastructure, or broader campaign history.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted campaign distributing Milum remote-control trojan to organizations including industrial-sector entities; active since at least Aug 2019; tooling not code-linked to known APT per the report.
A Middle East-focused campaign distributing a mature C++ trojan against industrial-related entities, using victim-specific RC4 keys.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.