An unnamed, likely nation-state-linked threat network associated with a long-running fraudulent online gambling operation. The activity has reportedly persisted for more than a decade and combines cybercrime monetization with infrastructure and tradecraft consistent with advanced persistent threat operations. The network is assessed to target government and private-sector organizations in the United States and Europe while also operating illicit gambling services aimed at Indonesian-speaking users. The actor’s infrastructure is notable for its scale and dual-use design. It has been associated with large numbers of attacker-controlled and hijacked domains, including compromised subdomains belonging to legitimate organizations. Reported tradecraft includes exploitation of poorly secured WordPress and PHP applications, subdomain hijacking through dangling DNS and CNAME weaknesses, deployment of backdoors such as GSocket, abuse of reverse proxies on legitimate domains to disguise command-and-control traffic, and SEO manipulation to drive traffic to fraudulent services. The operation has also been linked to malicious Android application distribution and use of code-hosting platforms to stage malware. Observed behaviors indicate both cybercriminal and espionage-oriented utility. The network has been tied to credential harvesting at scale, potential theft of session cookies through hijacked subdomains, covert communications routed through trusted infrastructure, and access-enabling post-compromise capabilities. Victim organizations reportedly span government, manufacturing, transport, healthcare, and education. Although the activity has been described as state-sponsored or state-linked in sophistication and operational model, no specific government sponsor has been directly attributed with high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.