Corkow is a financially motivated cybercriminal group associated with targeted intrusions against financial institutions, particularly in Russia. The group has been linked to attacks on POS terminals, ATMs, and trading terminals, and is also referenced alongside other major Russian banking intrusion groups active since at least 2013, including Anunak, Buhtrap, and Lurk. Corkow is part of the wave of organized bank-focused operations that demonstrated how attackers could move beyond commodity malware into tailored compromises of financial networks and payment environments. The group is associated with targeted attacks on banks and financial infrastructure rather than indiscriminate crimeware activity. Reported tradecraft for this class of operations includes phishing-based initial access, use of legitimate or freely available administrative tools during intrusions, and attempts to leverage insider knowledge or assistance to better understand internal systems and facilitate malicious actions. Corkow has also been specifically tied to an attack on Russia's Energobank in 2016. Corkow is additionally referenced as both a threat group and a banking Trojan active in Russia, reflecting overlap between the actor and malware used in its operations. Available information supports characterization of Corkow as a Russian-speaking cybercriminal actor focused on theft from financial organizations and related payment technologies.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an active group targeting banking-adjacent financial infrastructure including POS terminals, ATMs, and trading terminals.
Named as one of the early groups conducting attacks on Russian banks and financial institutions.
Financially motivated group referenced for a 2016 attack on Russia's Energobank involving market/FX manipulation impacts; included as a comparative example of stock/market manipulation methods.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.