CryptoLove is a Russian-speaking cybercrime group associated with cryptocurrency scam activity and malware distribution. It has been identified as part of the broader Russian-speaking cybercrime ecosystem and has been linked to sub-teams including Scamquerteo. CryptoLove has been associated with ClickFix-style social engineering operations in which victims are lured through fake service pages and deceptive prompts into manually executing malicious commands, bypassing browser-based protections and conventional download warnings. Operations linked to CryptoLove and its sub-team infrastructure have impersonated widely used online services, including videoconferencing and other consumer software themes, to deliver infostealer malware to both Windows and macOS users. Malware families associated with these campaigns include StealC, Rhadamanthys, Lumma Stealer, and Atomic macOS Stealer. Reported delivery methods include phishing, compromised websites, fake verification or error dialogs, and malicious web templates shared across related criminal clusters. Observed post-delivery behavior includes theft of credentials and other sensitive data, as well as broader post-compromise access that can enable remote control and follow-on exploitation. CryptoLove appears to operate through sub-teams and shared criminal services, with indications of common templates and infrastructure used alongside other groups such as Marko Polo and its sub-team Slavic Nation Empire. The actor’s activity reflects financially motivated cybercrime centered on social engineering, malware delivery, credential theft, and data exfiltration rather than espionage or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CryptoLove is a cybercrime group whose sub-team Scamquerteo is involved in the ClickFix campaign, sharing infrastructure and templates with other groups to distribute infostealers via fake service pages.
CryptoLove is a Russian-speaking cybercrime group focused on cryptocurrency scams and infostealer malware campaigns. They leverage the ClickFix tactic to trick users into installing malware by impersonating legitimate services.
CryptoLove is a cryptocurrency scam gang with sub-teams involved in ClickFix campaigns distributing info-stealing malware via phishing and social engineering.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.