Milton Group is a transnational call-center fraud network associated with large-scale investment scam operations that targeted victims through fraudulent online trading schemes. The network operated across multiple countries, including Ukraine, Georgia, and Albania, and used different internal and customer-facing brand identities, including Morgan Limited. Court-linked reporting ties a central figure in the network to management of an Albania-based operation active from 2017 to 2019 and to the development and sale of PumaTS, a proprietary customer-management and trading platform that enabled the scam model to scale and be replicated by other criminal groups. The group’s operations relied on trained call-center agents posing as investment advisers, building trust with targets, and persuading them to deposit funds into fake trading environments controlled by the operators. Victims were promised substantial returns, but funds were not genuinely invested and were instead misappropriated by the network. The operation reportedly employed hundreds of staff at peak scale and caused substantial financial losses, including significant harm in German-speaking countries. The associated PumaTS platform was assessed by a court to have facilitated broader fraud activity beyond the original call centers by supporting additional criminal operators. Milton Group is best characterized as an organized financially motivated fraud enterprise rather than a state-backed intrusion set. The available facts support social-engineering-based initial victim engagement, use of spoofed professional identities, and theft of victim funds through deceptive investment workflows. High-confidence reporting does not establish ransomware activity or classic network-intrusion tradecraft such as persistence, lateral movement, or privilege escalation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.