SUDO_MOM2025 is an intrusion operator associated with a Remcos RAT distribution and command-and-control operation attributed to a Colombian individual identified as TELLEZ FABIAN. The activity involved openly exposed staging infrastructure delivering a multi-stage infection chain that used script-based droppers, PowerShell execution, an in-memory .NET loader, and process hollowing into a legitimate Windows process to deploy Remcos RAT v7.2.0. Attribution is supported by the use of the SUDO_MOM2025 GitLab identity, the TELLEZ FABIAN name, and operational overlap with related repositories and exposed infrastructure. The operation used commodity remote-access malware rather than bespoke tooling. The deployed Remcos configuration and loader chain indicate capabilities for credential theft, keylogging, clipboard monitoring, screenshot capture, webcam and audio capture, remote shell access, file management, process injection, persistence, and user account control bypass. The infection workflow demonstrates initial access through malware delivery, post-exploitation remote administration, defense evasion through in-memory loading and process hollowing, and data collection from infected hosts. The actor’s tradecraft appears opportunistic and criminal rather than state-directed. The exposed infrastructure and poor operational security suggest a relatively unsophisticated operator compared with mature espionage groups, but the malware capabilities still enable full remote surveillance and theft from compromised systems. Known aliases directly tied to this activity include SUDO_MOM2025 and TELLEZ FABIAN.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.