SwapSushi is a crypto-focused threat actor associated with the malicious Chrome extension MEXC API Automator and related SwapSushi-branded Telegram and social-media infrastructure. The actor has been linked with moderate confidence to the publisher handle jorjortan142 and appears to be Russian-speaking based on Russian-language code comments, but country-level attribution is not established at high confidence. The actor’s operations center on theft of cryptocurrency by abusing authenticated sessions on the MEXC exchange. In the documented activity, a malicious browser extension masqueraded as an automation utility for exchange API management and trading workflows. Once installed, it programmatically created new API keys inside the victim’s active MEXC session, enabled withdrawal permissions, concealed those permissions in the user interface so they appeared disabled, and exfiltrated the generated API credentials to attacker-controlled Telegram infrastructure. This gave the actor programmatic control over victim exchange accounts without needing account passwords or bypassing two-factor authentication, enabling unauthorized trading and withdrawals. Observed tradecraft includes session hijacking through abuse of an already authenticated browser session, credential theft of newly generated API keys and secrets, defense evasion through deceptive user-interface manipulation, and exfiltration to attacker-controlled messaging infrastructure. The activity is financially motivated and focused on cryptocurrency theft rather than espionage or disruptive objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crypto-focused theft operation using a trojanized Chrome extension to hijack authenticated MEXC sessions, create API keys with withdrawal permissions (while masking that permission state in the UI), and exfiltrate API credentials to a Telegram bot for account draining.
Operates a crypto-themed cluster distributing a malicious Chrome extension (“MEXC API Automator”) via the Chrome Web Store to steal newly created MEXC API keys/secrets with withdrawal permissions, conceal the withdrawal permission state in the UI, and exfiltrate credentials to a hardcoded Telegram bot for subsequent account takeover and fund theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.