MoscowTeam is a likely Russian-speaking cybercriminal threat actor associated with a custom malware platform internally labeled "MoscowTeam_Steal." The operation combines multiple capabilities in a single intrusion chain, including information stealing, remote access and botnet control, ransomware deployment, and probable DDoS-oriented tasking. The malware architecture uses a staged loader and in-memory execution to decrypt and reflectively load an embedded payload, reducing on-disk artifacts and complicating analysis. The actor’s tooling is designed to automate compromise from execution through monetization. Its stealer functionality targets browser-stored credentials, cryptocurrency wallet data, messaging application data, clipboard contents, screenshots, system profiling information, and other user and host artifacts. After data theft and exfiltration, the malware registers with command-and-control infrastructure and can retrieve additional components used for ransomware operations. MoscowTeam’s ransomware capability includes service and process termination intended to disable backup, database, and security software before encrypting files across local, removable, and network-accessible drives. The ransomware can continue encryption even without live command-and-control connectivity through embedded cryptographic material, and it uses anti-forensic wiping behavior after encryption. Persistence is established through user-level autorun mechanisms for both the initial malware and the ransomware component. The botnet and post-compromise framework supports operator tasking such as process injection, command execution, SOCKS proxying, scanning, payload deployment, and sleep or interval control. The malware also includes anti-analysis and defense-evasion features, including checks for debugging, monitoring, and reverse-engineering tools as well as virtualization-aware execution guards. Attribution is tentative but points to a Russian-speaking actor based on internal branding and operational characteristics. No high-confidence evidence directly supports specific victim countries or sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.