CryptoMimic is an advanced persistent threat actor active since around 2018 that has conducted targeted intrusions against international businesses, with a particular emphasis on banks, financial organizations, and cryptocurrency-related companies. Known aliases include Dangerous Password, CageyChameleon, Leery Turtle, and CryptoCore. The actor has been observed targeting organizations worldwide, including victims in Japan, Russia, Europe, and the United States. CryptoMimic commonly gains initial access through spearphishing emails or LinkedIn messages that deliver links to cloud-hosted archives. These lures typically use password-protected decoy documents alongside malicious shortcut files, and the intrusion chain has also included macro-enabled Office documents and CHM files. Observed operations used staged VBScript-based malware and multiple downloader components to establish execution and persistence, followed by deployment of several Cabbage RAT variants for interactive command-and-control and victim triage. The group’s tooling supports reconnaissance, command execution, file upload and download, directory listing, and execution of additional scripts or payloads. CryptoMimic has demonstrated selective victim filtering, including collecting host information and deciding whether to continue or terminate an intrusion based on target attractiveness or prior visibility. Later stages of observed attacks included theft of Google Chrome cookies and stored passwords, deployment of msoRAT for broader remote access and process manipulation, PE injection, and activity involving LSASS. The actor also deployed a credential stealer that abused the Windows Security Package mechanism for persistence and credential access. CryptoMimic has shown notable defense-evasion tradecraft, including anti-analysis checks for security products, rapid replacement or invalidation of delivery infrastructure, deletion of malware artifacts, termination of processes, and clearing of Windows event logs after operations. In at least one observed case, cleanup and destructive actions left the victim system unable to boot. Multiple researchers have noted similarities between CryptoMimic and Lazarus-linked activity in targeting, lure formats, malware traits, and operational patterns, but definitive attribution to Lazarus has not been established on the available evidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated intrusion activity targeting banks, finance-related organizations, and especially cryptocurrency companies worldwide using spear-phishing, LNK files, macro documents, staged VBScript RATs, information stealers, and credential theft tooling.
Financially motivated intrusion group targeting financial organizations, especially cryptocurrency companies, using spear-phishing via email or LinkedIn, LNK/CHM/macro-based initial access, staged VBScript RATs ('Cabbage RAT'), browser and credential theft, and follow-on RAT activity via msoRAT.
Financially motivated intrusion activity targeting banks, finance-related organizations, and especially cryptocurrency companies worldwide using spear-phishing, LNK files, macro documents, staged VBScript RATs, information stealers, and credential theft tooling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.