Operation FrostBeacon is a financially motivated cybercrime campaign targeting business-to-business enterprises in the Russian Federation. The operation focuses on finance- and legal-related functions inside victim organizations, including teams responsible for payments, contracts, reconciliation, debt collection, and legal risk. Reported victim sectors include logistics, industrial production, construction, and technical supply. The campaign uses spearphishing as its primary initial access vector. Observed lures impersonate urgent business correspondence such as payment disputes, legal claims, debt repayment demands, and reconciliation notices. Two principal infection chains have been associated with the operation: archive attachments containing malicious shortcut files disguised as documents, and weaponized office documents exploiting CVE-2017-0199 and CVE-2017-11882. In both cases, execution leads to remote script retrieval and a heavily obfuscated PowerShell-based loader. Operation FrostBeacon is notable for layered defense evasion and fileless execution. The loader uses multiple stages of encoding and in-memory shellcode execution, followed by process injection into legitimate Windows processes. The final payload is Cobalt Strike Beacon, used for persistent access, command-and-control, post-exploitation activity, lateral movement, and data exfiltration. The operators also blend malicious traffic with legitimate-looking web requests and use customized Cobalt Strike tradecraft to reduce detection. Available reporting assesses the operators as a Russian-speaking cybercrime group likely operating from Russia and primarily targeting the Russian B2B economy. Although some tactics overlap with activity associated with Cobalt Group, Operation FrostBeacon has been treated as a distinct campaign rather than conclusively attributed to a previously established named cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operation FrostBeacon is a financially motivated Russian-speaking cybercrime group conducting targeted phishing and exploit-based attacks against Russian B2B enterprises, primarily in logistics, industrial production, and construction sectors, to deploy Cobalt Strike for persistent access and data exfiltration.
A Russian-speaking, financially motivated cybercrime group conducting multi-cluster phishing and malware campaigns (Operation FrostBeacon) targeting Russian B2B enterprises, especially finance and legal departments, using Cobalt Strike beacons delivered via weaponized archives and malicious documents exploiting legacy vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.