Kaspersky identified DeathStalker, a long-running hacker-for-hire group that targeted European law firms and fintech companies, with additional victims in the Middle East including Israel, Jordan, and Egypt. Researchers said the group appeared focused on stealing business and financial intelligence rather than conducting traditional state espionage, marking it as part of a broader mercenary APT market in which private operators sell intrusion capabilities to paying clients.
The intrusions typically began with spear-phishing emails carrying weaponized .LNK shortcut files that launched PowerShell-based backdoors. Reporting on mercenary threat actors placed DeathStalker alongside groups such as Bahamut, DarkBasin, Candiru, and NSO Group, underscoring how commercial surveillance and hacking services are increasingly used against not only activists and dissidents but also enterprises. Researchers noted that, despite the sophistication associated with mercenary operators, campaigns like DeathStalker’s often still rely on familiar weaknesses such as phishing susceptibility and poor patching.

Get the infrastructure and lures behind it.
17 events from the most recent confirmed update back to the earliest known activity.
In September 2021, the US Department of Justice announced that three former US intelligence employees were fined $1.69 million and barred from receiving security clearances for supporting UAE hacking operations tied to Project Raven.
In November 2020, BlackBerry disclosed CostaRicto, a mercenary APT that targeted organizations worldwide using spear-phishing, stolen credentials, and the custom SombRAT backdoor.
In August 2020, Kaspersky disclosed DeathStalker as a Russian-speaking mercenary APT targeting law firms and financial institutions with custom malware and dead-drop resolvers on public platforms.
On July 29, 2020, Kaspersky disclosed a hacker-for-hire group it initially codenamed Deceptikons, describing its targeting of European law firms and fintech companies for business and financial intelligence.
On July 16, 2020, the UK NCSC published an advisory on malicious activity using WellMess malware to target COVID-19 vaccine research institutions and attributed the activity to APT29.
Kaspersky reported that the domains emro-who[.]in and emro-who[.]org were registered on June 21, 2020 and used as sender domains for spear-phishing.
In June 2020, Citizen Lab disclosed that DarkBasin had targeted thousands of individuals and hundreds of institutions, including advocacy groups, journalists, officials, and nonprofits tied to #ExxonKnew.
On May 28, 2020, the US NSA published an alert describing Hades exploiting CVE-2019-10149 in Exim as part of a potentially large mass-access operation.
On May 15, 2020, EGI-CSIRT published an alert describing two incidents targeting academic data centers for CPU mining and included indicators of compromise.
On May 11, 2020, the UK supercomputing center ARCHER announced it was shutting down network access while it investigated a security incident affecting its facility.
Kaspersky attributed with high confidence a watering-hole campaign in March 2020 that delivered Cobalt Strike via DLL side-loading to the HoneyMyte threat actor.
Kaspersky observed an increase in the number of WellMess command-and-control servers in February 2020, which it cited as part of a cyclical pattern of activity.
Kaspersky described a CactusPete campaign starting in December 2019 that deployed an updated DoubleT backdoor via a malicious dropper placed in the Microsoft Word Startup directory.
Kaspersky said DeathStalker conducted a spear-phishing campaign against European law firms in 2019, using malicious LNK files that launched PowerShell-based backdoors.
WellMess malware was originally described by LAC Co in 2018, establishing an early public reference point for later campaigns discussed by Kaspersky and NCSC.
The earliest compilation timestamps for CostaRicto's custom SombRAT backdoor date to 2017, indicating the group's operations were underway by that year.
In an updated technical report published on August 24, 2020, Kaspersky renamed the mercenary group Deceptikons to DeathStalker.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cyjax.com
Open sourcesecurelist.com
Open sourcezdnet.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.