GeorgeGinx is a likely financially motivated cybercriminal operator or small intrusion team associated with Striker command-and-control infrastructure and bespoke remote-access management tooling. The actor has been linked to trojanized software distribution, including a fake Microsoft Teams installer that deploys a weaponized RustDesk client, indicating an evolution from operating C2 infrastructure to distributing signed malware for hands-on-keyboard intrusion activity. Infrastructure attributed to GeorgeGinx includes a Striker C2 deployment and a separate Flask-based panel explicitly branded "GeorgeGinx Panel," with supporting Go-based backend services and custom DNS functionality. Embedded operator branding and Telegram-linked identifiers connect these systems to the same actor. Observed Striker functionality included agent management, interactive shell access, tasking, file operations, redirector management, authentication key handling, team chat, user administration, and logging. The actor demonstrates capabilities consistent with post-compromise remote administration and malware operations, including command-and-control over web protocols, payload delivery, interactive command execution, and likely data movement from victim systems. Use of a trojanized legitimate application installer and a signed payload indicates defense-evasion tradecraft through masquerading and abuse of code-signing trust. The infrastructure also exposed services suggestive of broader criminal experimentation or adjacent activity, including a panel themed around trading bot management, but the strongest attribution centers on malware delivery and C2 operations rather than a confirmed separate fraud cluster. GeorgeGinx has also been associated with the alias or operator handle "calipology" and with Striker-related operations. Available evidence supports characterization as an intermediate-capability criminal actor with relatively weak operational security rather than a state-sponsored group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster from a prior investigation tied here through overlapping infrastructure and attribution artifacts with the calipology operator and Striker C2 operations.
An activity cluster/operator running a Striker C2 deployment alongside a bespoke Flask-based "GeorgeGinx Panel" on Evoxt infrastructure. The operator exposed a Telegram handle in the panel HTML and appears to support hands-on-keyboard intrusions with interactive console, tasking, file operations, redirectors, and possible DNS-based C2/tunneling capability.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.