GS7
GS7 is an elusive, financially motivated threat actor assessed to operate a long-running phishing and brand-impersonation operation dubbed “Operation DoppelBrand,” observed prominently from December 2025 through January 2026 (with reporting indicating activity history stretching back to at least 2022). The actor targets Fortune 500 and other high-value organizations—especially U.S. financial services (e.g., Wells Fargo, USAA, Navy Federal Credit Union, Fidelity Investments, Citibank) and also technology, healthcare, telecommunications, insurance, and investment firms—using high-fidelity cloned login portals and large-scale lookalike domain infrastructure. Operation DoppelBrand tradecraft includes registering and rotating hundreds of impersonation domains (over 150 identified in recent months, with ~200 additional related domains reported) and proxying traffic through Cloudflare to obscure origin infrastructure. Reported infrastructure patterns include one-year domain registrations, automated SSL issuance (e.g., Let’s Encrypt / Google Trust Services shortly after domain creation), wildcard DNS, and consistent subdomain/TLS fingerprinting patterns. Phishing pages capture credentials and victim telemetry (e.g., IP address, geolocation, device/browser fingerprinting, timestamps) and exfiltrate results in near real time via attacker-controlled Telegram bots/groups (e.g., “NfResultz by GS,” “WfResultz by GS”). Beyond credential theft, GS7 commonly abuses legitimate remote monitoring and management (RMM) tools—reported examples include LogMeIn/LogMeIn Resolve, AnyDesk, and ScreenConnect—delivered via MSI installers and VBS loader scripts that may attempt privilege elevation (UAC loops), perform silent installation (msiexec), and remove artifacts. Reporting assesses GS7 likely functions as an Initial Access Broker (IAB), monetizing via sale of harvested credentials and resale of compromised access on Telegram channels/underground markets, potentially enabling follow-on activity by other criminal groups including ransomware affiliates. The actor has been linked in reporting to underground Telegram channels and Brazilian cybercrime forums used for trading stolen credentials and financial data. No geographic attribution for GS7’s operators is provided in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated phishing/credential-harvesting actor using brand impersonation, lookalike domains, and Telegram bots; may function as an initial access broker and/or deploy RMM tooling for persistence/remote access.
Financially motivated initial access broker running large-scale phishing with cloned portals to steal credentials, then monetizing access by selling credentials; also drives victims to install legitimate RMM tools for persistent remote access.
Financially motivated phishing and initial-access-broker activity targeting major brands: clones banking/tech portals to steal credentials, then pushes victims to install legitimate remote access/RMM tools for persistence; monetizes by selling credentials on Telegram/underground markets.
Financially motivated phishing/impersonation operation leveraging large-scale domain spoofing to harvest credentials and exfiltrate data via Telegram bots; also delivers legitimate RMM tooling (e.g., LogMeIn Resolve) plus MSI installers and VBS loaders to enable stealthy installation, privilege escalation, and removal.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.