DarkGaboon is a threat actor observed targeting Russian entities. The group has been associated with the use of legitimate administrative utilities, living-off-the-land techniques, and off-the-shelf malware rather than uniquely attributed bespoke tooling. Public reporting places DarkGaboon alongside Rare Werewolf in campaigns against organizations in Russia, indicating an intrusion style centered on blending malicious activity with normal system administration behavior to reduce detection. Based on the available high-confidence information, DarkGaboon is linked to initial access and post-compromise activity that relies on legitimate tools and defense-evasion-oriented tradecraft. Attribution beyond the actor name, including country of origin, broader victimology, or a more specific operational mandate, is not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.