NOMADS is a malware-as-a-service operation associated with the previously unreported information stealer MefStealer. The group appears to have been in a pre-operational stage at the time it was identified, with exposed infrastructure indicating no confirmed victims yet. Its operation included a FastAPI-based command-and-control dashboard, a Flask-based stealer gate, and openly exposed monitoring components, reflecting significant operational security failures. MefStealer is designed to collect and exfiltrate credentials, browser cookies, and other browser-derived data from infected systems. The exposed management interfaces indicated support for handling victim logs, stolen data, and configuration through a REST-based backend. The group’s activity therefore aligns with credential theft, session hijacking through cookie theft, and data exfiltration as core capabilities. Known aliases and associated operator handles include Chernuha, Forust or MrForust, Hudan, and Xdfnx, which were presented as members of the NOMADS group. Chernuha has been linked to infrastructure architecture, Forust to server-related configurations, Hudan was described as less exposed operationally, and Xdfnx as a developer. Infrastructure linkages and residential network evidence point to Slovakia as the most strongly supported geographic nexus for the group. NOMADS is best characterized as a financially motivated cybercriminal actor operating a stealer-focused MaaS ecosystem rather than a nation-state intrusion set. No high-confidence evidence supports ransomware deployment, destructive activity, or espionage operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.