BENTONITE is an opportunistic espionage-focused threat actor observed conducting offensive cyber operations against exposed enterprise infrastructure. The group has been associated with exploitation of widely disclosed vulnerabilities, including Log4j and VMware Horizon flaws, to gain access to remote access systems and other internet-facing assets. Reported tradecraft includes living-off-the-land techniques to establish and maintain persistence within victim environments, indicating reliance on native system tools and legitimate administrative functionality rather than bespoke malware alone. High-confidence reporting supports espionage as the dominant motivation, but publicly available information in this context does not substantiate specific victim countries, sectors, or a definitive national affiliation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducts espionage and disruptive operations against oil & gas and manufacturing, exploiting vulnerabilities for initial access and deploying downloader malware.
Uses Living Off The Land (LOTL) tactics to maintain persistent access in victim environments.
Uses Living Off The Land (LOTL) tactics to maintain persistent access in victim environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.