UNK_RemoteRogue is a suspected Russian espionage threat cluster observed in late 2024 using ClickFix-style social engineering against defense-sector targets. The group sent phishing emails from likely compromised mail infrastructure and used lures spoofing Microsoft Office to direct victims to attacker-controlled pages with Russian-language instructions, including guidance to copy and execute commands manually. In the documented infection chain, victim execution triggered JavaScript and then PowerShell associated with the Empire command-and-control framework, indicating hands-on post-compromise capability and use of legitimate administration-style tooling patterns common in espionage operations. The cluster has been linked to targeting individuals at organizations associated with major arms manufacturing firms, and infrastructure overlap has also been noted with separate phishing activity aimed at defense- and aerospace-related entities connected to the war in Ukraine for credential harvesting. Based on observed targeting, delivery, and tooling, UNK_RemoteRogue is best characterized as a Russia-linked cyber-espionage actor focused on defense-related intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected Russian actor using ClickFix-style lures spoofing Microsoft Office to drive PowerShell/JavaScript execution and deploy Empire C2 against defense-industry-associated targets.
Russian state-linked activity cluster observed using ClickFix in campaigns targeting the defense industry.
Espionage targeting defense/arms manufacturing using ClickFix lures to drive JavaScript then PowerShell execution, leveraging Empire for post-exploitation.
Used ClickFix lures delivered from compromised Zimbra servers to drive victims to a fake Microsoft Word page (with Russian instructions and a YouTube tutorial) that executed JavaScript to launch PowerShell and connect to an Empire C2 server.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.