Skip to main content
Mallory
2 malware families

STAC4365

Also known asSTAC4365

STAC4365 is an affiliate group of the Qilin ransomware operation. It has been reported to rely on an adversary-in-the-middle (AitM) phishing kit to steal credentials. Qilin is a ransomware-as-a-service (RaaS) operation, also known as Agenda, Gold Feather, Phantom Mantis, and Water Galura, that was first observed in July 2022 and uses double extortion involving file encryption and data theft. Qilin affiliates have been observed gaining initial access via phishing and social engineering, valid credentials, external remote services, and exploitation of public-facing applications, and the malware can target Windows and Linux/ESXi environments. The broader Qilin operation has used Golang and Rust ransomware variants, including the Rust-based Qilin.B variant, and has been associated with credential harvesting, domain policy/GPO modification, EDR bypass and kill techniques including BYOVD and EDRSandblast, log clearing, shadow copy deletion, and lateral movement with tools such as PsExec. Microsoft tracks the group behind Qilin’s operation, management, and leadership as Storm-1934. The provided content identifies STAC4365 specifically as a Qilin affiliate subgroup using AitM phishing for credential theft.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics15 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1566
Phishing
T1566.002×2
Spearphishing Link
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
1 technique
T1078
Valid Accounts
TA0006
Credential Access
2 techniques
T1056
Input Capture
T1056.004
Credential API Hooking
T1557
Adversary-in-the-Middle
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.006
Windows Remote Management
TA0009
Collection
2 techniques
T1056
Input Capture
T1056.004
Credential API Hooking
T1557
Adversary-in-the-Middle
TA0040
Impact
1 technique
T1486
Data Encrypted for Impact
ACTIVITY FEED

Recent activity

1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping7

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.