ITG26 is a cybercrime cluster associated with the QakBot and Pikabot malware ecosystems. The available reporting links this actor to financially motivated criminal activity and places it within the broader trend of identity-focused intrusion operations that emphasize phishing-delivered malware, credential theft, and rapid monetization. Activity associated with this cluster is consistent with initial access operations that rely on social engineering and malware delivery rather than destructive objectives. ITG26 has been associated with malware families used to establish footholds and support follow-on intrusion activity. In the observed context, the actor is tied to campaigns involving phishing and infostealer-style tradecraft that enable credential harvesting and unauthorized access. Such operations align with broader cybercriminal patterns of using stolen identities and valid accounts to reduce attacker dwell time, evade detection, and facilitate downstream compromise. High-confidence attribution in the available facts supports characterization of ITG26 as a financially motivated cybercrime actor associated with credential-focused intrusion activity. Specific country of origin, victim-country concentration, industry specialization, and ransomware or extortion tactics are not established by the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.