Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation Emmental

Operation Emmental

TLP:CLEAR
Active

Also known as: Retefe Gang, Retefe Group

Description

Operation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012. They primarily target customers of banks in countries such as Austria, Sweden, Switzerland, and Japan. The group has developed sophisticated malware, including a Mac alternative called Dok, to bypass two-factor authentication and hijack network traffic. They have also been observed using phishing emails to spread their malware. The group is believed to be Russian-speaking and has continuously improved their malicious codes over the years.

AI Analysis

· 1 week ago

Executive Summary

Operation Emmental, also known as the Retefe Gang, is a persistent threat actor targeting financial sector customers in Austria, Sweden, Switzerland, and Japan since at least 2012. The group uses sophisticated malware to bypass two-factor authentication and phishing campaigns to steal credentials for financial gain.

Goals & Targeting

Operation Emmental targets individuals within the financial sector to achieve financial gain through credential theft and banking fraud. Their focus on countries with robust financial systems indicates a strategic approach to maximizing financial returns. Typical victims include bank customers in Austria, Sweden, Switzerland, and Japan, chosen for their access to valuable financial resources.

Enhanced Description

Operation Emmental, or Retefe Group, is a financially motivated cyber threat group active since 2012. They primarily target banking customers in select European countries and Japan, using advanced tactics like phishing and malware development. Their sophisticated toolkit includes the Dok malware, designed to bypass two-factor authentication on macOS systems, showcasing their technical proficiency. Over the years, they have refined their techniques to enhance their attack effectiveness, consistently focusing on financial fraud and credential theft.

Key Capabilities

  • Development of sophisticated malware (e.g., Dok)
  • Phishing campaigns
  • Two-factor authentication bypass
  • Network traffic hijacking

Software / Tooling

Dok Malware

Campaigns & Victims

Operation Emmental has demonstrated a long operational lifespan, consistently targeting financial sector individuals. Their campaign patterns include prolonged campaigns and continuous improvement of their attack methods, reflecting a determined and adaptive threat group.

IOC Patterns

  • Spear-phishing emails
  • Distribution of malicious Office documents
  • Use of malware to hijack network traffic
  • Attempts to bypass two-factor authentication

Recommended Actions

  • Implement comprehensive employee training on phishing detection
  • Regularly update and patch software
  • Monitor network activity for suspicious behavior
  • Enhance multi-factor authentication with additional layers
  • Deploy threat detection tools like sandboxes

Suggested Tags

APT
Financial Sector
Cybercrime
Banking TTPs

Confidence Assessment

Confidence in the assessment is moderate. While operational details and targets are well-documented, gaps exist regarding specific tools, MITRE techniques, and exact campaign specifics beyond targeting parameters.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Phishing
APT
Financial Sector
Cybercrime
Banking TTPs

Details

Type
Unknown
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.