jorjortan142 is a threat actor handle associated with a malicious browser-extension campaign targeting users of the MEXC cryptocurrency exchange. The actor was linked to a Chrome extension marketed as an automation utility for trading and API key creation, but designed to abuse an already authenticated browser session to create exchange API credentials with elevated permissions, including withdrawals, and then steal those credentials for subsequent account takeover and fund theft. The operation relied on a Manifest V3 Chrome extension that activated on MEXC’s API-management workflow. It programmatically interacted with the API key creation interface, enabled broad permissions, and manipulated the page’s visual state so that withdrawal access appeared disabled to the victim while remaining enabled on the service side. After the exchange displayed the newly created credentials, the extension scraped the access and secret keys from the page and exfiltrated them over HTTPS to attacker-controlled Telegram infrastructure. This tradecraft allowed the actor to obtain long-lived exchange API credentials without stealing passwords directly and without bypassing two-factor authentication, instead waiting for the victim to complete normal authenticated actions. The actor’s observed capabilities center on session abuse, credential theft in the form of API-key theft, defense evasion through UI deception and blending into normal browser traffic, and crypto theft through downstream automated trading and withdrawals. The handle has also been linked in reporting to SwapSushi-branded social presence and infrastructure. Available reporting notes Russian-language comments in the malicious code, indicating a likely Russian-speaking developer, but this does not support high-confidence country attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with a malicious Chrome extension (“MEXC API Automator”) that performs in-browser account takeover of MEXC users by silently creating/scraping API keys with trading and withdrawal permissions and exfiltrating them to attacker-controlled Telegram infrastructure.
Operates a malicious Chrome extension (“MEXC API Automator”) distributed via the Chrome Web Store to steal newly-created MEXC exchange API keys (including withdrawal permissions) by automating key creation inside an authenticated session, deceptively hiding the withdrawal permission in the UI, and exfiltrating the API key/secret to a hardcoded Telegram bot for subsequent account takeover and fund theft. The same operator is moderately confidently linked to “SwapSushi” branded Telegram/X/YouTube infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.