ConfCrew is a cybercriminal malware delivery and access service associated with Gozi-related operations and overlapping infrastructure and tradecraft used in Valak campaigns. The actor has been linked to spam-driven intrusion chains, including reply-chain email hijacking, malicious document delivery, script-based loaders, and staged DLL execution. Activity attributed to ConfCrew shows a service-oriented model in which delivery infrastructure, campaign tracking, and payload deployment are provided to customers, with telemetry and panel functionality consistent with a load service. ConfCrew-linked operations have used multi-stage, script-heavy infection chains delivered through fake installers, malicious links, and compromised websites. Observed techniques include PE polyglot abuse involving Microsoft-signed DLLs with appended script content executed via mshta, extensive security-control weakening on victim hosts, staged payload decryption, and selective payload deployment based on victim profiling. In enterprise-like environments, campaigns have deployed tools such as Cobalt Strike and AteraAgent, while other victims received banking malware including Gozi and Zloader. The actor’s ecosystem has also been associated with Valak delivery patterns and enterprise-focused credential theft. Overlapping campaign structure, URL conventions, and PHP-based delivery proxies have caused some automated systems to misclassify Valak activity as Gozi. Related operations used compromised web infrastructure and proxy scripts to retrieve campaign files from backend systems and to track hits, operators, filenames, and link performance. Plugins associated with this ecosystem harvested Exchange, Office, and email credentials from Windows Credential Manager and stored application data, supporting further reply-chain abuse and broader post-compromise access. ConfCrew is best characterized as a financially motivated Russian-linked cybercrime service supporting malware distribution, credential theft, defense evasion, and post-exploitation for downstream payload operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
79 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to a malware delivery service using signed-DLL polyglot techniques and fake installers to deploy different payloads depending on whether the victim appears to be in an enterprise environment.
Operates Gozi-related delivery and spam services, including reply-chain/thread hijacking campaigns, and appears operationally linked to or overlapping with Valak delivery infrastructure and email-harvesting activity.
Operates a Gozi-associated delivery and spamming service linked to reply-chain email hijacking campaigns. The content connects ConfCrew infrastructure and tactics to Valak delivery, including compromised servers, PHP delivery proxies, campaign tracking panels, and harvesting email data for spam propagation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.