SteelClover is a financially motivated cybercrime threat actor active since at least 2019 and associated with malware distribution campaigns that impersonate legitimate software brands to infect victims. The group has been linked to activity overlaps with Malsmoke, Batloader, DEV-0569, and Water Minyades. Its operations have prominently targeted organizations in Japan and have used malicious search-engine advertising and cloned software download sites to deliver malware under the guise of trusted applications. SteelClover commonly relies on commodity or commercially available tooling rather than bespoke exploit development. Observed delivery chains have used MSI and MSIX installers, PowerShell execution, and abuse of Windows packaging features to launch follow-on payloads. The actor has used defense-evasion measures including anti-analysis checks and modification of Microsoft Defender exclusions. Post-compromise activity has included deployment of information stealers such as Ursnif and RedLine Stealer, with Ursnif variants providing remote access capability and RedLine used for theft of sensitive data from infected endpoints. Reporting also indicates SteelClover intrusions have in some cases progressed to ransomware execution. In 2023, SteelClover was observed using a modular PowerShell malware family known as PowerHarbor. PowerHarbor includes a downloader that fingerprints hosts, performs target selection, and retrieves a main module that maintains encrypted command-and-control communications and executes additional modules. Observed modules include StealData, which collects system information, browser-stored credentials, credentials from applications such as Telegram, FileZilla, and WinSCP, and cryptocurrency wallet information; Scheduler, which establishes persistence through PowerShell profile modification, registry-based user shell folder changes, and scheduled tasks; and GetBrowsers, which inventories installed browsers. The malware also includes virtual-machine detection and deletes modules after execution, indicating deliberate defense evasion and modular post-exploitation capability. Available evidence indicates likely Russian-speaking operators, based on language artifacts and operational details. SteelClover is best characterized as a cybercriminal intrusion set focused on malware delivery, credential and data theft, persistence, and follow-on monetization, with occasional progression toward ransomware-related outcomes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses the newly observed modular PowerShell malware PowerHarbor in active attack operations. The malware includes downloader, main module, credential-stealing, persistence, and browser-enumeration modules.
Google広告を悪用して著名ソフトウェアを模倣した配布サイトへ誘導し、MSI→PowerShell→GPG復号の流れでUrsnifとRedline Stealerを配布する金銭目的の攻撃を実施。情報窃取に加え、最終的にランサムウェア実行に至るケースもある。
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.