Y2K Operators is a threat cluster associated with the active deployment of Millenium RAT, a malware-as-a-service remote access trojan targeting Windows systems globally. The cluster has been linked to large-scale infections across more than 160 countries, with activity accelerating sharply in early 2026. Millenium RAT is reportedly developed by an actor using the handle ShinyEnigma, while Y2K Operators appears to function as an operational cluster distributing and using the malware in campaigns. The group primarily relies on social engineering for initial access rather than software exploits. Observed lures include fake game cheats, cracked software, hacking tools, credit card generators, crypto-related utilities, and trojanized offensive-security tools. In some cases, the operators reportedly backdoored other malware and exploit-builder tools to infect would-be cybercriminal users. Campaign delivery has also included shortcut-based infection chains that silently launch PowerShell to retrieve payloads while displaying decoy content. Capabilities associated with Y2K Operators through Millenium RAT include credential theft, browser data theft, session theft, keylogging, screenshot capture, webcam and audio capture, arbitrary file download and execution, persistence, attempted privilege escalation through user-approved elevation prompts, and file encryption. The malware has also been observed masquerading as legitimate Windows components after installation and using techniques intended to hinder detection, including a native C++ implementation, embedded encrypted configuration data, and hash-changing modifications to evade signature-based defenses. Command and control is conducted through the Telegram Bot API, allowing operators to blend malicious traffic with legitimate messaging-related network activity and avoid maintaining dedicated command-and-control servers. Y2K Operators is best characterized as a financially oriented cybercriminal cluster operating within the malware-as-a-service ecosystem. No high-confidence attribution to a nation state is established in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
59 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat cluster actively deploying Millenium RAT v4 at scale. The campaign uses Telegram Bot API for command-and-control and supports credential theft, keylogging, screenshot and audio capture, arbitrary code execution, and full system compromise across a large global victim base.
Operating campaigns distributing Millenium RAT at scale via social engineering, including booby-trapped downloads disguised as game cheats, cracked software, and hacking tools; also observed backdooring attacker tools so other criminals infect themselves.
Operating and scaling distribution of Millenium RAT as part of a broad malware campaign targeting Windows users globally via social-engineering lures and trojanized tools.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.