Gro_oza, also referred to as grooza, is a cybercriminal persona associated with smishing and mobile-focused phishing infrastructure used to harvest victim credentials. The actor is linked to phishing clusters that impersonate government and telecom-related services and that are delivered through SMS campaigns leveraging compromised or exposed industrial cellular routers. Infrastructure associated with this activity has targeted recipients in multiple European countries, notably Belgium, Sweden, Italy, and France. Gro_oza is associated with the operation of a Telegram bot known as GroozaBot, which has been used to log visitor interactions from phishing pages. The phishing kits tied to this cluster include anti-analysis and traffic-filtering features, such as device detection to restrict access to mobile users and JavaScript intended to hinder inspection and debugging. Reporting also links the actor to a Grooza or GroozaV2 phishing cluster that uses supporting artifacts hosted on third-party developer content platforms. Observed tradecraft indicates a focus on initial access through SMS phishing, credential theft via spoofed login portals, reconnaissance of victim interactions through Telegram-based logging, and defense evasion through mobile-only rendering and anti-analysis scripting. The activity is consistent with financially motivated cybercrime rather than espionage. Available reporting indicates the operator appears to speak Arabic and French, but high-confidence attribution to a specific state or formal intrusion set is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gro_oza is associated with smishing (SMS phishing) campaigns that abuse vulnerable industrial cellular routers to send phishing messages at scale. The actor operates phishing websites that collect credentials and uses Telegram bots for logging victim interactions.
Smishing/phishing activity cluster leveraging exposed/abused Milesight industrial cellular router SMS APIs to distribute phishing URLs at scale, with infrastructure and phishing kits linked via shared domains/IPs, JavaScript artifacts (e.g., maghat_lebssouch.js), and Telegram-based logging (GroozaBot). Impersonates multiple brands (e.g., CSAM/eBox, Telia, postal/banking/ID services) to steal banking/payment credentials; uses mobile-only rendering checks to evade automated analysis.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.