HackingTeam was an Italian offensive security and surveillance vendor that developed and sold intrusion software marketed to government, law-enforcement, and intelligence customers. Its flagship platform was Remote Control System (RCS), also known across versions and reporting as DaVinci, Galileo, Crisis, Morcut, and Korablin. Although not a conventional intrusion set in the same sense as a state APT or criminal crew, HackingTeam operated and maintained mature spyware capabilities across multiple operating systems, including Windows, macOS, Linux desktop, iOS, and Android. RCS was a full-featured surveillance framework designed for covert endpoint compromise, collection, and remote control. Documented capabilities included keylogging, microphone and webcam capture, screenshots, browser surveillance, interception or recording of messaging activity, encrypted command-and-control over HTTP, and persistence through user-level launch mechanisms on macOS. Some variants also used kernel components for stealth, including hiding files and processes. Delivery methods included exploit-based infection and social engineering, and public reporting tied HackingTeam tooling to exploitation of Adobe Flash vulnerability CVE-2015-5119. macOS tooling associated with HackingTeam showed comparatively advanced tradecraft for its era, including custom packing, use of Apple binary encryption features for obfuscation, anti-debugging, dynamic symbol resolution, encrypted configuration and log storage, bundle injection into GUI applications, and LaunchAgent persistence. Public analysis of the OS X implant known as Crisis showed modular architecture with dropper, backdoor, injected components, encrypted configuration, and optional kernel extensions. HackingTeam infrastructure has also been observed using satellite-linked IP space for command-and-control, indicating efforts to complicate attribution and infrastructure disruption. HackingTeam became especially notable after a major 2015 breach attributed in public reporting to Phineas Phisher. The compromise exposed a large volume of internal data, including source code and customer information, and accelerated public reverse engineering of its implants. The leak also enabled broader reuse and study of HackingTeam tooling by other actors. HackingTeam is best understood as a commercial spyware developer and operator supporting government surveillance missions, with primary motivation aligned to espionage-oriented intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial surveillance vendor whose leaked RCS/Galileo tooling included Linux-capable malware later acquired and used by threat actors.
HackingTeam is distributing a new version of their RCS (Remote Control System) implant for OS X, using an encrypted and packed installer to evade detection. The implant achieves persistence via a Launch Agent and drops encrypted configuration files. The malware is not detected by traditional antivirus solutions.
Commercial intrusion tooling vendor whose command-and-control servers have been observed hosted on satellite IP ranges (satellite-based Internet links) to increase resilience/anonymity.
Commercial intrusion tooling vendor whose command-and-control infrastructure has been observed hosted on satellite IP space (used as an anonymity/resilience layer).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.