Hopper is a previously undocumented adversary-in-the-middle phishing operation and phishing-as-a-service kit focused on real-time credential and session theft against Microsoft authentication workflows. It proxies legitimate Microsoft login activity to capture usernames, passwords, multifactor authentication responses, and authenticated session tokens, enabling account compromise even when conventional MFA is enabled. Hopper has been associated with a multi-hop redirect architecture designed for tracking, anti-bot filtering, token generation, victim routing, and final proxy delivery, indicating a mature and actively maintained phishing platform. Observed Hopper tradecraft includes deep redirect chains used for evasion, real-time proxying of authentication sessions, and framework-specific handling of authentication state consistent with ASP.NET Core and OpenID Connect implementations. Reported fingerprints include origin rewriting behavior and direct setting of authentication-related cookies on the phishing infrastructure rather than simple relay from the legitimate service. The operation has also shown rapid lure rotation across multiple brand themes, suggesting either an actively developed kit or a service used across multiple campaigns. Hopper has targeted organizations across multiple sectors, including financial services, health care, energy, and international or public-interest organizations. Its lure themes have included common enterprise and productivity brands as well as delivery-themed social engineering. The combination of customized proxy infrastructure with more generic lure content is consistent with a service-oriented phishing ecosystem rather than a single bespoke intrusion set. Known AiTM and PhaaS families such as Tycoon 2FA, Mamba 2FA, Sneaky 2FA, Gabagool, and Evilginx have been reported as ruled out in this case based on absent code-level indicators, supporting Hopper’s treatment as a distinct cluster. No high-confidence attribution to a specific country, state sponsor, or named criminal group is currently available. Hopper’s dominant motivation is best assessed as financial, given its phishing-for-access model and PhaaS characteristics.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.