ScopeCreep is the name given to a Russian-speaking threat actor activity cluster associated with development and deployment of a Go-based Windows malware campaign. The operation used strong compartmentation and account-cycling behavior, creating numerous short-lived accounts and using each for narrowly scoped incremental development tasks, indicating deliberate operational security practices. The campaign distributed malware through a trojanized software repository impersonating a legitimate gaming utility. Infection involved a loader that retrieved additional payloads and launched a multi-stage intrusion chain. Reported functionality included privilege escalation, stealthy persistence, defense evasion, and theft of sensitive browser-stored data. The malware sought to harvest credentials, tokens, and cookies from web browsers and exfiltrate them to the operators. It also supported operator notifications through Telegram when new victims were compromised. Observed tradecraft included use of PowerShell to attempt Microsoft Defender exclusions, console suppression, timing delays, Base64 obfuscation, DLL side-loading, and proxying through SOCKS5 infrastructure to conceal operator origin. The malware development workflow included iterative debugging and refinement of Go code, HTTPS communications, and integration of messaging-based alerting. The activity has been characterized as limited in observed spread rather than a broadly deployed campaign. No additional verified aliases or sub-groups are established beyond the ScopeCreep designation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.