HEXSTRIKE is a likely financially motivated threat actor, assessed as an individual or small team, associated with advanced web application exploitation, supply-chain compromise, credential theft, and post-compromise operations. The actor has been linked to a Russian-language FortiGate mass exploitation campaign and to a targeted npm supply-chain intrusion against a cryptocurrency exchange. Available evidence supports operation from or strong association with Russian-speaking infrastructure and tooling. HEXSTRIKE operated an exposed Russian-language dashboard and API server used to manage large-scale exploitation of FortiGate devices worldwide. The campaign tracked thousands of targets across more than 200 countries and recorded confirmed compromises, stolen credentials, internal host discovery, and extensive command execution against victim environments. Reported intrusion chains involved exploitation of FortiGate vulnerabilities including CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762, followed by reuse of decrypted administrative and VPN credentials for internal reconnaissance, lateral movement, and broader domain compromise. Observed follow-on tradecraft included use of EternalBlue, SMBGhost, and PrintNightmare for movement inside victim networks. The actor also conducted a targeted software supply-chain attack through malicious npm packages impersonating Strapi plugins. Those packages used post-install execution to deploy a multi-phase command-and-control agent that harvested environment variables, database credentials, JWT secrets, Redis data, Docker and Kubernetes secrets, SSH material, and wallet-related files, then established command polling and reverse-shell access. Recovered tooling showed follow-on exploitation of Strapi via CVE-2023-22621 server-side template injection, abuse of stolen PostgreSQL credentials to alter application state and hijack password-reset workflows, credential stuffing against employee accounts, attempted container escape, and interception of authentication material from internal services. Known victimology includes government, military-adjacent, health-related, nonprofit or research, sports, and cryptocurrency-related organizations. Specifically identified impacted entities span Thailand, Senegal, Mali, Brazil, Italy, India, and Estonia. The actor’s operations indicate strong capability in initial access, credential theft, reconnaissance, lateral movement, post-exploitation, exfiltration, and defense-evasion, with emphasis on monetizable access and theft of sensitive operational data rather than disruptive or ideological outcomes. No high-confidence evidence in the available facts supports ransomware deployment or extortion branding by HEXSTRIKE.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A financially motivated threat actor or small team conducting a targeted npm supply-chain compromise against the Guardarian cryptocurrency exchange. The operation used 9 malicious Strapi-themed npm packages with postinstall hooks to deploy a multi-phase C2 agent, steal credentials and secrets, exploit Strapi SSTI for remote code execution, attempt container escape, perform credential stuffing, intercept Elasticsearch credentials, and enable lateral movement.
Russian-speaking activity cluster conducting large-scale FortiGate exploitation, credential extraction, internal reconnaissance, lateral movement, and domain-admin compromise against enterprise, government, military, research, and other organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.