Red WinterDog is a Mexico-based cybercriminal threat actor focused on credential and information theft against users in Mexico. The actor is associated with the BlackDog and BlackBelen malware families and is notable for abusing malicious browser extensions targeting Google Chrome and Microsoft Edge. Its operations are designed to steal banking credentials, personal information, and business email account access. Red WinterDog commonly obtains initial access through malvertising on search engines and has also used phishing themes that impersonate Mexican government entities, including RENAPO and SAT, to increase victim trust and reach. The actor has leveraged highly searched Mexico-related themes to lure victims into installing malicious content. BlackDog has been delivered through malicious JavaScript and HTML-based infection chains that culminate in installation of a rogue browser extension, while BlackBelen has been observed being installed directly through official browser extension marketplaces. A defining characteristic of Red WinterDog activity is man-in-the-browser behavior. Its malware can redirect victims from legitimate banking workflows to fraudulent pages or inject malicious content into legitimate banking sessions to capture credentials and other sensitive data. The actor also regularly updates its tooling and tradecraft to evade detection and complicate analysis. Observed activity spans from at least June 2022 through May 2023.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.