Scamquerteo is a threat group identified as a sub-team of the cryptocurrency scam gangs Marko Polo and CryptoLove. It has been linked to ClickFix social-engineering campaigns that impersonate collaboration and productivity services to trick victims into executing malicious code. These operations have used fraudulent meeting pages and other lure themes, including fake conferencing platforms, software utilities, video games, web3 projects, and messaging applications, to deliver information-stealing malware to both Windows and macOS users. Scamquerteo’s observed tradecraft centers on phishing and user-execution deception. Victims are enticed through messages that mimic legitimate meeting invitations or technical prompts, then manipulated into copying and running PowerShell commands that retrieve additional payloads. Associated malware delivery has included commodity stealers such as Stealc, Rhadamanthys, and Atomic macOS Stealer. The group’s activity demonstrates strong social-engineering capability, cross-platform targeting, and a focus on credential and data theft rather than disruptive or destructive effects. Observed targeting has included transport and logistics organizations, with campaign activity notably reported against victims in the United States and Japan. Scamquerteo appears financially motivated, consistent with its association with broader cryptocurrency scam ecosystems and infostealer-driven theft operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.