CryptoChameleon, also tracked as UNC5356, is a financially motivated phishing-focused threat cluster known for advanced social-engineering operations against cryptocurrency users, cryptocurrency platforms, password-manager users, and related enterprise targets. The actor is associated with credential-harvesting campaigns that impersonate trusted brands and services, including LastPass, and has been linked to phishing activity targeting credentials, passkeys, and session material rather than malware deployment. The group is notable for multi-channel social engineering, including phishing emails, SMS and phone-based phishing, and support impersonation. Reported campaigns have abused legitimate business workflows and emotionally manipulative pretexts, such as LastPass emergency-access or inheritance themes, to coerce victims into authenticating on spoofed portals. Operations attributed to CryptoChameleon have targeted master passwords for password managers, credentials for cryptocurrency exchanges and wallets, and in some cases passkeys protected by FIDO2/WebAuthn workflows. The actor has also been linked to phishing kits capable of generating convincing sign-in pages for multiple major identity and consumer platforms. CryptoChameleon has been described as operating with scalable phishing infrastructure and as being distributed or enabled through phishing-as-a-service ecosystems. Activity associated with the cluster includes overlap with AI-assisted phishing tooling such as COINBAIT, a cryptocurrency-themed credential-harvesting kit, and broader tradecraft aligned with MFA-resistant phishing operations seen in adjacent clusters. Reporting also notes loose alignment or overlap with Scattered Spider and PoisonSeed, and association with adjacent clusters including Crimson Collective and the SLH umbrella discussed in extortion-focused reporting, though CryptoChameleon itself is primarily evidenced here as a phishing and credential-theft actor rather than a ransomware operator. Victimology centers on the cryptocurrency ecosystem, financial services, enterprise users of identity and email platforms, and organizations whose employees can be manipulated through trusted SaaS or password-management brands. Observed tradecraft includes reconnaissance and target selection, initial access via phishing and spoofing, credential theft, session abuse, and data exfiltration of harvested account information. The dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Group associated with SMS and phone phishing; linked in the report to activity around the COINBAIT phishing kit (crypto-exchange credential theft).
Financially motivated cluster assessed to overlap with activity involving the CoinBait phishing kit (credential-harvesting kit masquerading as a cryptocurrency exchange), reportedly accelerated by AI code generation tools.
Financially motivated cluster linked to aspects of COINBAIT activity (AI-generated phishing kit masquerading as a cryptocurrency exchange for credential harvesting).
Referenced as a possible match for the TTPs in a credential-phishing campaign leveraging compromised email-service infrastructure (SendGrid) and CAPTCHA-gated redirection to credential-harvesting sites.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.