ESET detailed Operation Potao Express, a long-running cyber-espionage campaign built around the Win32/Potao malware family and, in some cases, a trojanized TrueCrypt variant tracked as Win32/FakeTC. The activity was first observed in 2011 and targeted victims primarily in Ukraine, Russia, and Georgia, including Ukrainian government, military, and media organizations as well as members of the MMM Ponzi scheme. Researchers said the operation relied heavily on social engineering rather than software exploits, using phishing emails, spear-phishing SMS messages, fake postal-service websites, malicious executables disguised as documents, and USB-based propagation.
The malware functioned as a modular espionage toolkit with plugins for system profiling, file theft, password theft, screenshots, and keylogging, while command-and-control traffic was protected with RSA-2048 and AES-256. ESET also found that truecryptrussia.ru selectively served backdoored TrueCrypt downloads to chosen victims and simultaneously acted as command-and-control infrastructure, reinforcing the view that the campaign was professionally run and highly selective. The report did not make a definitive attribution, but said the malware was probably of Russian origin and highlighted several high-value Ukrainian targets among the victims.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
The attackers later registered the domain WorldAirPost.net in June 2015 as part of the postal-themed Potao infrastructure.
Since March 2015, ESET detected Potao binaries at several high-value Ukrainian targets, including government and military entities and a major news agency. The lures used filenames themed around prisoners, captivity, and the Anti Terrorist Operation in Eastern Ukraine.
In March 2015, the operators used another fake postal site, WorldAirPost.com, with a design stolen from Singapore Post and relabeled as Italy Post.
In March 2014, Potao operators used a fraudulent postal-themed website named MNTExpress modeled on the legitimate Pony Express site. The campaign sent spear-phishing SMS messages containing each victim’s full name, cellphone number, and a specific tracking code required to download the malware.
ESET detected several Potao debug versions in autumn 2013 and inferred they may have preceded later targeted attacks against Ukrainian victims. One debug-wave campaign ID was krim, the Russian word for Crimea.
A 2013 Potao sample in Georgia used the filename Wedding_invitation.exe and displayed a decoy wedding invitation in English.
In June 2012, Sergei Mavrodi warned that spear-phishing emails impersonating him were directing MMM members to malware hosted on Dropbox.
ESET telemetry indicated that truecryptrussia.ru had been serving malware since at least June 2012, distributing selectively backdoored Russian-language TrueCrypt binaries detected as Win32/FakeTC and also hosting Potao infrastructure.
Potao campaigns in 2012 used social-engineering lures aimed at members or organizers of the MMM Ponzi scheme in Russia and Ukraine.
An early 2011 Potao campaign delivered executables disguised with Microsoft Word icons and embedded decoy documents. One 2011 campaign used an Armenian-language decoy document belonging to the Armenian Ministry of Labor and Social Affairs.
ESET reported that the Win32/Potao malware family was first seen in attacks in 2011, marking the beginning of the Operation Potao Express activity it analyzed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.