SKRX is a Russian-speaking cybercriminal threat actor associated with the handle 68sheff and linked to the development and operation of a custom Python-based Windows infostealer dropper. The actor has been tied with high confidence to malware campaigns targeting gamers and general Windows users for credential and session theft, host profiling, and data exfiltration. Observed collection objectives include account data and tokens associated with gaming and communication platforms, browser cookies and session material, clipboard contents, screenshots, antivirus details, and broader system inventory information. The malware also retrieves additional payloads, stages stolen data locally, compresses the results, and exfiltrates them over encrypted web traffic. Operationally, SKRX has demonstrated defense-evasion behavior by disabling or weakening Microsoft Defender protections and hiding staged data in obscured temporary directories. The malware uses a multi-stage infection flow in which an initial PyInstaller-packed executable downloads and launches a second-stage payload. Collection behavior includes theft of browser session material, platform tokens, and other locally stored secrets, indicating both credential-theft and session-hijacking capability. The actor’s tooling also supports screenshot capture and clipboard theft, expanding post-compromise visibility into victim activity. SKRX is also linked to a Russian-language Telegram Mini App branded as SKRX SHOP that appears to offer Russian phone verification numbers by region, behavior consistent with financially motivated fraud enablement and abuse of phone-based account verification workflows. Taken together, the actor’s activity is most consistent with financially motivated cybercrime centered on infostealer operations, account compromise, and related fraud services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.