Okrum is a threat actor tracked for espionage-oriented intrusion activity. Reported tradecraft includes use of a keylogger to capture keystrokes from compromised systems and use of Base64 encoding to obfuscate command-and-control communications. These behaviors indicate capability for credential collection and covert post-compromise communications. High-confidence public facts in scope support keylogging and encoded C2 traffic, but do not establish broader targeting patterns, sector focus, or confirmed national attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses a keylogger tool to capture keystrokes.
Uses Base64 encoding for C2 communications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.