TaskMasters is a long-running espionage and data-theft threat actor identified in 2018 and named for its unusual use of Windows Task Scheduler task creation for lateral movement. The group’s primary objective is theft of confidential information combined with long-term persistence inside victim networks. Investigations have linked the actor to compromises dating back to at least 2010, indicating sustained operational activity over many years. TaskMasters has primarily targeted manufacturing and industrial organizations, while also compromising entities in energy, government, science and technology, systems integration, software development, geology, transport and logistics, real estate, and construction. A significant concentration of victims has been observed in Russia and other CIS countries. The actor combines custom malware with widely available offensive tooling. Its principal malware family is RemShell, a backdoor used for remote command execution that includes a downloader and a main payload. RemShell uses encrypted and compressed payload delivery and a multi-stage command-and-control architecture in which an initial proxy can hand off infected hosts to other servers dynamically. TaskMasters has also used web shells, including ASPXSpy2014 and a disguised IIS 404-style web shell, to maintain backup access and manage compromised systems. Observed tradecraft includes internal reconnaissance, exploitation of vulnerabilities including CVE-2017-0176, deployment of toolkits after initial compromise, credential theft using utilities such as Mimikatz and PWDump, remote execution, file collection and archiving, and exfiltration of stolen data to command infrastructure. The group has used AtNow to execute commands on remote hosts through scheduled tasks, alongside tools such as NbtScan and PSExec to support network discovery and movement within victim environments. Supply-chain intrusion activity has also been associated with the actor. Attribution to China has been discussed based on multiple artifacts and operational clues, but should be treated cautiously. Reported indicators include Chinese-linked infrastructure and tooling artifacts, as well as operational traces suggesting Chinese nexus. However, shared tools and reused malware components limit confidence in stronger attribution beyond a China-linked assessment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced for comparison because the group reused self-signed certificates with identical metadata across servers, aiding infrastructure tracking.
Criminal espionage-focused intrusion set targeting primarily manufacturing/industrial organizations (also energy, government, science/tech, systems integration, software, geology, transport/logistics, real estate, construction). Operates with long-term persistence, credential theft, lateral movement via scheduled tasks (AtNow/Task Scheduler), and data theft/exfiltration to C2; uses web shells as backup access and performs supply-chain attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.