LARVA-290 is an individual associated with the Russian-speaking threat cluster commonly tracked as Nebulous Mantis, which has also been linked to aliases including Cuba, STORM-0978, Tropical Scorpius, and UNC2596. LARVA-290 is identified as playing a central operational support role by acquiring and managing bulletproof hosting infrastructure used for command-and-control and ransomware-related operations. This infrastructure support underpins campaigns that blend cyber-espionage tradecraft with criminal monetization and extortion activity. The broader cluster supported by LARVA-290 has targeted government entities, critical infrastructure, political figures, and NATO-related defense organizations since at least 2019. Its operations have relied on spear-phishing for initial access, followed by staged payload delivery, encrypted command-and-control, credential harvesting, host and network reconnaissance, domain discovery, persistence through COM hijacking, and data exfiltration. The group has used the Hancitor loader historically and later shifted to the RomCom remote access trojan as a primary platform, alongside supplementary tooling for tunneling, archiving, and domain enumeration. It has also employed defense-evasion measures including anti-sandbox checks and environmental awareness techniques. The threat activity associated with this ecosystem has included ransomware deployment as cover for espionage operations, with campaigns tied over time to Cuba, Industrial Spy, and Team Underground. Within that ecosystem, LARVA-290 appears to function as an enabling operator focused on resilient hosting and infrastructure management rather than as a separately distinct intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.