Akodon is a threat actor associated with the Shadow Vector malware campaign targeting users in Colombia. The activity is characterized by spear-phishing emails impersonating trusted Colombian institutions and legal entities, often using urgent judicial-themed lures to induce victims to open malicious attachments or retrieve staged payloads from public hosting services. The campaign has delivered commodity remote access malware including AsyncRAT and RemcosRAT through multistage infection chains designed for stealth, persistence, and credential-focused surveillance. Observed tradecraft includes malicious SVG-based delivery, staged script downloaders, DLL side-loading, process hollowing and injection, anti-analysis checks, and persistence through scheduled tasks and autorun mechanisms. In RemcosRAT-related chains, the actor has also used vulnerable kernel drivers for privilege escalation and included logic to enumerate and terminate security tooling. Newer iterations have used modular, memory-resident .NET loaders, in-memory execution via PowerShell reflection, and UAC bypass through trusted Windows utilities. The operation has shown strong emphasis on credential theft, banking-related theft, keylogging, and full remote access, with tooling and code characteristics suggesting overlap or code reuse with Portuguese-speaking financially motivated malware ecosystems. High-confidence attribution to a specific nation state is not supported.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.