Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
87 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Brazil-focused banking-malware operation that uses document-themed JavaScript lures, multi-stage loaders, a SentinelOne DLL-sideloading chain, and malicious Chromium browser extensions to steal credentials, cookies, session tokens, browser data, and sensitive information. It uses Ethereum smart contracts as dead-drop resolvers for dynamic C2 and payload locations.
Cybercriminal operation conducting Brazilian banking fraud through Portuguese-language lures impersonating banks. It deploys the KREMLIN loader and a malicious Chromium extension to steal browser credentials, cookies and session data, log keystrokes, capture screens, inject or intercept web content, and redirect victims. Its delivery chain uses manually executed JavaScript, Node.js, scheduled-task persistence, sandbox checks, DLL side-loading, and Ethereum smart contracts as a dead-drop resolver for payload and C2 configuration.
A Brazil-focused financially motivated banking-malware operation active since at least May 2025. It uses the KREMLIN toolkit to deliver malicious Chromium extensions and RAT payloads, steal browser credentials, cookies, session tokens, keystrokes, page content, and intercepted web-request data. The operation uses JavaScript/PowerShell/Node.js loaders, RunPE and DLL sideloading, Ethereum smart contracts as dead-drop resolvers for dynamically changing infrastructure, and lures impersonating Brazilian banks and payment services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.