GS7 is a financially motivated cybercriminal threat actor associated with large-scale phishing, credential theft, and follow-on access monetization. The group is best known for Operation DoppelBrand, a brand-impersonation campaign active at least during late 2025 through early 2026 that targeted Fortune 500 organizations and their customers, particularly in financial services, as well as technology, healthcare, telecommunications, insurance, and related sectors. Targeting has been concentrated on English-speaking markets, especially the United States, but activity has also affected organizations globally. GS7 specializes in high-fidelity phishing portals that closely mimic legitimate enterprise and consumer login pages in order to harvest usernames, passwords, and related victim telemetry. The actor has operated a large, frequently rotated phishing infrastructure with extensive use of lookalike domains, automated certificate provisioning, and traffic proxying or shielding services to complicate detection and takedown. Reporting has linked the operation to hundreds of phishing-related domains over time, including more than 150 associated with recent campaign waves. The group’s tradecraft extends beyond simple credential collection. GS7 has been observed exfiltrating stolen credentials and victim metadata in near real time to attacker-controlled Telegram bots or channels, enabling rapid operational use. Collected information has included device, browser, geolocation, and timing data that can support account takeover and victim triage. Some lures have used urgency themes such as account verification or security updates, and some phishing flows have redirected victims into staged interfaces designed to increase trust and completion rates. A notable aspect of GS7 activity is the abuse of legitimate remote monitoring and management tools after credential capture or social-engineering success. Observed tooling has included products such as LogMeIn, AnyDesk, and ScreenConnect, sometimes delivered through scripted loaders and silent installer chains. This behavior indicates an objective of establishing persistent remote access on victim systems while blending into normal administrative activity. The actor has also been associated with installer and script-based delivery mechanisms intended to elevate privileges, reduce user suspicion, and remove artifacts after installation. GS7 is widely assessed as functioning at least in part as an initial access broker. In addition to harvesting credentials directly, the actor appears to monetize operations by selling stolen credentials, compromised account access, or footholds in victim environments to other criminal actors, potentially including ransomware affiliates. The group has also been linked to underground Telegram channels and Brazilian cybercrime forums used for trading stolen credentials and financial data. Known aliases are limited, with GS7 and the shortened form GS both used in reporting. No high-confidence public attribution ties GS7 to a nation-state sponsor. The available evidence supports characterization as a financially motivated criminal actor with mature phishing infrastructure, strong brand-impersonation capability, and a business model centered on credential theft, remote access enablement, and resale of compromised access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting credential-harvesting phishing campaigns against major enterprises using sophisticated phishing kits, highly accurate brand impersonation, and automated batch domain registration.
Financially motivated phishing/credential-harvesting actor using brand impersonation, lookalike domains, and Telegram bots; may function as an initial access broker and/or deploy RMM tooling for persistence/remote access.
Financially motivated initial access broker running large-scale phishing with cloned portals to steal credentials, then monetizing access by selling credentials; also drives victims to install legitimate RMM tools for persistent remote access.
Financially motivated phishing and initial-access-broker activity targeting major brands: clones banking/tech portals to steal credentials, then pushes victims to install legitimate remote access/RMM tools for persistence; monetizes by selling credentials on Telegram/underground markets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.