Also known as: Retefe Gang, Retefe Group
Operation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012. They primarily target customers of banks in countries such as Austria, Sweden, Switzerland, and Japan. The group has developed sophisticated malware, including a Mac alternative called Dok, to bypass two-factor authentication and hijack network traffic. They have also been observed using phishing emails to spread their malware. The group is believed to be Russian-speaking and has continuously improved their malicious codes over the years.
Executive Summary
Operation Emmental, also known as the Retefe Gang, is a persistent threat actor targeting financial sector customers in Austria, Sweden, Switzerland, and Japan since at least 2012. The group uses sophisticated malware to bypass two-factor authentication and phishing campaigns to steal credentials for financial gain.
Goals & Targeting
Operation Emmental targets individuals within the financial sector to achieve financial gain through credential theft and banking fraud. Their focus on countries with robust financial systems indicates a strategic approach to maximizing financial returns. Typical victims include bank customers in Austria, Sweden, Switzerland, and Japan, chosen for their access to valuable financial resources.
Enhanced Description
Operation Emmental, or Retefe Group, is a financially motivated cyber threat group active since 2012. They primarily target banking customers in select European countries and Japan, using advanced tactics like phishing and malware development. Their sophisticated toolkit includes the Dok malware, designed to bypass two-factor authentication on macOS systems, showcasing their technical proficiency. Over the years, they have refined their techniques to enhance their attack effectiveness, consistently focusing on financial fraud and credential theft.
Key Capabilities
Software / Tooling
Campaigns & Victims
Operation Emmental has demonstrated a long operational lifespan, consistently targeting financial sector individuals. Their campaign patterns include prolonged campaigns and continuous improvement of their attack methods, reflecting a determined and adaptive threat group.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the assessment is moderate. While operational details and targets are well-documented, gaps exist regarding specific tools, MITRE techniques, and exact campaign specifics beyond targeting parameters.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics