gigajew is a likely cybercriminal persona associated with development of a multi-stage malware delivery chain culminating in AsyncRAT. The attribution is based on a developer artifact embedded in a .NET loader namespace, indicating linkage to the HackForums handle "gigajew." The observed intrusion chain used spearphishing lures themed around pricing requests and technical documentation, suggesting targeting of manufacturing, engineering, or procurement personnel. The operation employed a staged infection flow beginning with a double-extension script attachment, followed by hidden PowerShell execution via WMI, retrieval of a steganographically concealed .NET loader from legitimate cloud-hosted infrastructure, and in-memory loading of that loader. The loader, identified as Fiber, then fetched and executed a subsequent payload using CasPol.exe as a living-off-the-land binary. Fiber also established persistence through both scheduled-task creation and a Registry Run mechanism, and incorporated virtual-machine and sandbox detection logic for defense evasion. The final payload was an AsyncRAT variant configured for broad post-compromise surveillance and remote access. Supported functionality included keylogging, active-window tracking, screen capture, webcam or microphone access, reverse shell capability, AES-encrypted command-and-control, and plugin-based extensibility. These behaviors indicate capabilities spanning initial access, persistence, defense evasion, credential and information theft, and general post-exploitation. Available evidence supports characterization of gigajew as a financially motivated cybercriminal actor or malware developer rather than a nation-state operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.