STAC6405 is a phishing-driven intrusion cluster tracked for abusing legitimate remote monitoring and management tools to obtain attacker-controlled unattended access to victim systems. Activity was observed from at least April 2025, with the bulk of known operations occurring in October and November 2025. The cluster affected more than 80 organizations, predominantly in the United States, across multiple sectors. The actor’s initial access tradecraft centers on invitation-themed and tender-themed phishing lures that direct victims to download legitimate remote access software preconfigured for attacker control. Observed tooling includes LogMeIn Resolve as the primary access mechanism and, in some cases, ScreenConnect. The use of legitimate administration software indicates a strong defense-evasion component and reduces the need to deploy overt malware during the initial compromise stage. In most observed intrusions, activity stopped after remote access was established, suggesting the operator often prioritized access establishment and retention over immediate hands-on-keyboard exploitation. This pattern is consistent with initial access brokerage or maintaining dormant persistence for later use. In a smaller number of cases, the actor moved quickly to second-stage activity after compromise. Observed follow-on activity included deployment of a HeartCrypt-packed infostealer and additional remote access components. The infostealer used delayed execution, hid user-visible cursor activity, injected into the legitimate Microsoft binary csc.exe, decrypted payload material at runtime, and harvested browser-stored credentials, session artifacts, cryptocurrency wallet data, and host information. Another intrusion used ScreenConnect together with Java-based components and a likely SimpleHelp-related remote access binary, and included firewall-rule enumeration before containment. Known aliases are limited to the tracking name STAC6405. No confirmed nation-state attribution is established. The cluster is best characterized as a financially motivated intrusion actor or access broker focused on phishing-based initial access, persistence through legitimate remote management tooling, credential and session theft in selected follow-on intrusions, and post-compromise remote administration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-led intrusion cluster targeting more than 80 organizations in the United States, using legitimate RMM tools such as LogMeIn Resolve and ScreenConnect to gain unauthorized access. The activity appears consistent with initial access broker behavior, with limited follow-on activity in most cases and rapid second-stage payload delivery in a small number of incidents.
A phishing-driven initial access campaign abusing legitimate RMM tools such as LogMeIn Resolve and ScreenConnect to gain unattended remote access to victim systems. In a small number of observed cases, follow-on activity included deployment of an infostealer and a Java-based remote access payload.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.