Skip to main content
Mallory
3 malware families

GS7

Also known asgs7

GS7 is an elusive, financially motivated threat actor assessed to operate a long-running phishing and brand-impersonation operation dubbed “Operation DoppelBrand,” observed prominently from December 2025 through January 2026 (with reporting indicating activity history stretching back to at least 2022). The actor targets Fortune 500 and other high-value organizations—especially U.S. financial services (e.g., Wells Fargo, USAA, Navy Federal Credit Union, Fidelity Investments, Citibank) and also technology, healthcare, telecommunications, insurance, and investment firms—using high-fidelity cloned login portals and large-scale lookalike domain infrastructure. Operation DoppelBrand tradecraft includes registering and rotating hundreds of impersonation domains (over 150 identified in recent months, with ~200 additional related domains reported) and proxying traffic through Cloudflare to obscure origin infrastructure. Reported infrastructure patterns include one-year domain registrations, automated SSL issuance (e.g., Let’s Encrypt / Google Trust Services shortly after domain creation), wildcard DNS, and consistent subdomain/TLS fingerprinting patterns. Phishing pages capture credentials and victim telemetry (e.g., IP address, geolocation, device/browser fingerprinting, timestamps) and exfiltrate results in near real time via attacker-controlled Telegram bots/groups (e.g., “NfResultz by GS,” “WfResultz by GS”). Beyond credential theft, GS7 commonly abuses legitimate remote monitoring and management (RMM) tools—reported examples include LogMeIn/LogMeIn Resolve, AnyDesk, and ScreenConnect—delivered via MSI installers and VBS loader scripts that may attempt privilege elevation (UAC loops), perform silent installation (msiexec), and remove artifacts. Reporting assesses GS7 likely functions as an Initial Access Broker (IAB), monetizing via sale of harvested credentials and resale of compromised access on Telegram channels/underground markets, potentially enabling follow-on activity by other criminal groups including ransomware affiliates. The actor has been linked in reporting to underground Telegram channels and Brazilian cybercrime forums used for trading stolen credentials and financial data. No geographic attribution for GS7’s operators is provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics25 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.001×3
Domains
TA0001
Initial Access
1 technique
T1566×3
Phishing
T1566.002×4
Spearphishing Link
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.005×2
Visual Basic
T1204×2
User Execution
TA0004
Privilege Escalation
1 technique
T1548
Abuse Elevation Control Mechanism
T1548.002
Bypass User Account Control
TA0005
Stealth
2 techniques
T1070
Indicator Removal
T1218
System Binary Proxy Execution
T1218.007
Msiexec
TA0006
Credential Access
3 techniques
T1003
OS Credential Dumping
T1056
Input Capture
T1056.003
Web Portal Capture
T1555
Credentials from Password Stores
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0008
Lateral Movement
1 technique
T1021×2
Remote Services
TA0009
Collection
1 technique
T1056
Input Capture
T1056.003
Web Portal Capture
TA0011
Command and Control
3 techniques
T1090
Proxy
T1090.003
Multi-hop Proxy
T1105×2
Ingress Tool Transfer
T1219×4
Remote Access Tools
TA0010
Exfiltration
1 technique
T1567×2
Exfiltration Over Web Service
ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping18

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.