ChainReaver, also referred to as RU-APT-ChainReaver-L, is a suspected Russian-linked threat activity cluster associated with a sophisticated multi-platform supply-chain campaign targeting Windows, macOS, and iOS users. The operation has been characterized by the compromise of software distribution channels, including mirror services and hijacked GitHub accounts, to deliver infostealers and phishing lures under the guise of legitimate or pirated software. The actor’s tradecraft emphasizes initial access through supply-chain compromise and social engineering. Victims are redirected through layered intermediary infrastructure designed to appear legitimate and reduce detection, with payload delivery frequently staged through trusted cloud-hosting providers. On Windows, the actor has distributed signed infostealer malware in password-protected archives. Reported functionality includes theft of browser credentials, screenshots, cryptocurrency wallet data, messaging application data, and user files. On macOS, the actor has used ClickFix-style deception to induce users to execute terminal commands that deploy MacSync Stealer in memory, with collection focused on browser data, cryptocurrency wallet material, SSH keys, and cloud credentials. On iOS, the campaign has used fraudulent VPN-themed applications as a precursor to phishing activity. ChainReaver has also been linked to the takeover and repurposing of established GitHub accounts to host malicious repositories and lures aimed at users seeking cracked software and activation tools. The operation reportedly rotates tooling, signatures, and delivery mechanisms frequently, and has used valid code-signing certificates to improve trust and evade security controls. Observed behavior supports assessment of a financially motivated actor focused on credential theft, cryptocurrency theft, and broader data exfiltration, with strong defense-evasion characteristics and cross-platform operational capability.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.