Aggah is a threat actor name used by third-party researchers and referenced by Proofpoint in connection with multiple malware campaigns. The provided content associates Aggah with use of NanoCore RAT and AveMariaRAT (WarZoneRAT), and with unattributed activity clusters involving Rhadamanthys. Proofpoint also reported a tax-themed malware delivery campaign from January 2025 that aligned with activity attributed by third parties to Aggah; in that campaign, a JavaScript file hosted on Microsoft Azure executed PowerShell, which deployed Rhadamanthys and then downloaded and executed zgRAT. Based on the content, Aggah is linked to commodity malware delivery and RAT/stealer operations rather than any stated nation-state affiliation. No additional aliases, sub-groups, or attribution details are provided in the content beyond the name Aggah.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Externally tracked threat actor associated with distributing Rhadamanthys as part of broader crimeware activity.
Associated with a tax-themed malware delivery campaign impersonating a tax software solutions organization. The campaign used a JavaScript downloader hosted on Microsoft Azure, which invoked PowerShell to execute Rhadamanthys, followed by download and execution of zgRAT.
Historically observed using NanoCore RAT in campaigns referenced by the content.
Listed as one of the threat groups observed using AveMariaRAT/WarZoneRAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.