Slavic Nation Empire (SNE) is a cybercriminal threat group associated with ClickFix social-engineering campaigns that deliver information-stealing malware to Windows and macOS users. The group has been identified as a sub-team linked to the cryptocurrency scam gangs Marko Polo and CryptoLove, indicating a broader criminal ecosystem centered on fraud and theft rather than state-directed operations. SNE has also been referenced alongside Scamquerteo in recent campaigns. SNE is known for phishing and impersonation activity that abuses fake meeting and collaboration themes, particularly counterfeit Google Meet pages, to trick victims into executing malicious commands. The group uses deceptive error prompts and other social-engineering lures to induce users to copy and run PowerShell code, resulting in malware delivery and follow-on compromise. Reported payloads in these campaigns include commodity and criminal-market stealers such as StealC, Rhadamanthys, and Atomic macOS Stealer, demonstrating cross-platform targeting and a focus on credential and data theft. Observed targeting includes users in the United States and Japan, as well as transport and logistics organizations. The group’s tradecraft reflects strong initial-access and spoofing capability through phishing, followed by credential theft, session or account compromise via infostealer deployment, and data exfiltration typical of stealer-led criminal operations. No high-confidence evidence in the available facts supports ransomware deployment or extortion by SNE itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Slavic Nation Empire is attributed to phishing campaigns exploiting fake Google Meet pages to distribute malware, similar to TA571.
Slavic Nation Empire (SNE) is a sub-team of larger cryptocurrency scam gangs and is involved in recent ClickFix campaigns, using phishing and social engineering to distribute info-stealing malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.