CARROTBALL is a malware-associated threat entity observed relying on user execution via malicious email attachments. Activity attributed to CARROTBALL involves luring targets into opening weaponized attachments delivered through email, indicating use of spearphishing-style initial access and social engineering to trigger execution on victim systems. Based on the available facts, the confirmed behavior is limited to attachment-based delivery and user-enabled execution; additional attribution, targeting patterns, geographic origin, sector focus, and broader post-compromise tradecraft are not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.