Fox is a threat actor designation associated with an iterative malspam campaign characterized as involving continuous intrusion and continuous distribution. Available high-confidence information indicates the actor has been linked to repeated malicious spam activity, but the currently available facts do not establish additional details about its malware families, victimology, geographic origin, sector targeting, operational scope, or broader intrusion tradecraft. No corroborated information is currently available to attribute Fox to a nation state, financially motivated cybercrime operation, or other specific actor category beyond its association with malspam activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster associated with an iterative malspam (malicious spam) campaign.
Iterative malspam (malicious spam) campaign activity attributed to the named cluster "Fox."
Iterative malspam (malicious spam) campaign activity characterized as continuous intrusion/continuous distribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.