Adversary Pursuit Group (APG) is a named intrusion investigation and tracking designation associated with activity involving exploitation of CVE-2026-48558 in SimpleHelp remote monitoring and management software. In the observed intrusion, the actor abused a critical OpenID Connect authentication bypass to obtain an authenticated technician session on an internet-facing RMM server without valid credentials, then leveraged the trusted remote management channel for follow-on access to managed endpoints. The operation involved deployment of TaskWeaver, a heavily obfuscated Node.js loader designed to evade static analysis, fingerprint hosts, establish encrypted command-and-control communications, and retrieve additional JavaScript payloads for execution. A linked second-stage payload, Djinn Stealer, functioned as a cross-platform information stealer targeting Windows, macOS, and Linux systems. Djinn Stealer was built to harvest a broad range of credentials and sensitive data, including cloud and infrastructure secrets, source control and package registry credentials, SSH material, browser data, deployment artifacts, and tokens associated with AI development tooling. It also searched for cryptocurrency wallet data and, on Linux, attempted to collect secrets exposed through process arguments and environment variables. The malware recursively traversed selected directories while excluding high-noise paths, then archived, compressed, encrypted, and exfiltrated collected data. The intrusion pattern demonstrates initial access through exploitation of a public-facing management platform, abuse of legitimate administrative channels for downstream compromise, staged malware delivery, credential theft, and data exfiltration. Attribution to a specific country, broader campaign cluster, or dominant motivation is not established by the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.