CryptoCore is a financially motivated cybercrime group active since at least 2018 that targets cryptocurrency exchanges and companies supporting the cryptocurrency trading ecosystem, including through supply-chain intrusion paths. The actor is also known as Crypto-gang, Dangerous Password, and Leery Turtle. Its operations have focused primarily on organizations in the United States and Japan, with the principal objective of gaining access to exchange wallets and employee-held wallet credentials in order to steal cryptocurrency. CryptoCore typically begins with extensive reconnaissance of target organizations, including executives, officers, IT personnel, and other key employees. The group commonly uses spear-phishing as its main initial access vector, often impersonating senior personnel from the victim organization or a related business partner. In some cases it first targets executives' personal email accounts before pivoting to corporate accounts. Campaign delivery has relied on cloud-themed lures, shortened links, compressed archives, shortcut-file downloaders disguised as benign documents, and Visual Basic Script payloads, including a backdoor tracked as CageyChameleon. Post-compromise, CryptoCore seeks access to password manager accounts that may contain wallet credentials, keys, and other assets useful for further compromise. The group has also used credential-dumping tooling to harvest passwords. It is characterized by patient persistence and operational timing: operators attempt to remain undetected inside victim environments until multi-factor authentication protecting wallets is removed, then move quickly to transfer funds. Reported tradecraft also includes host profiling, persistence mechanisms, and repeated reuse of similar phishing themes and payload chains against the same organizations over time. CryptoCore is assessed to have stolen tens of millions of dollars from cryptocurrency-related victims, with public estimates placing known thefts at roughly $70 million and possible total proceeds above $200 million over a two-year period. Attribution to a specific country is not conclusive, but reporting has linked the group with medium confidence to Eastern Europe, particularly Ukraine, Russia, or Romania.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
268 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated theft operations targeting cryptocurrency exchanges and related companies, using supply-chain intrusion, reconnaissance, spear-phishing, password manager access, persistence, and rapid wallet theft.
Threat actor targeting cryptocurrency exchanges and related companies, including via supply-chain attacks, to steal funds from exchange wallets. The group conducts reconnaissance, spear-phishing, credential theft, persistence, and wallet takeover operations, and is assessed to have stolen tens to hundreds of millions of USD.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.