Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Water Orthrus

Also known as: Cozy Bear, Fancy Bear, BlueBravo, APT29, APT28, Forest Blizzard, Cloaked Ursa, BlueDelta, Ethereal Panda, Carderbee, CVE-2023-38035, Storm-0401, Daggerfly, Bronze Highland, StormBamboo, Nobelium, Midnight Blizzard, The Dukes, SeedWorm, TEMP.Zagros, Static Kitten, APT-C-35, Origami Elephant, APT-C-36, APT43, Emerald Sleet, Sparkling Pisces, Springtail, TA427, Velvet Chollima, APT42, NiceCurl, TameCat, to infiltrate Windows machines, such as VPN services, compromised EdgeOS routers, to hide its tracks, carry out sophisticated attacks, Muddywater, APT36

Description

Water Orthrus is a threat actor known for distributing CopperStealer and CopperPhish malware. They target Microsoft 365 users with phishing campaigns to steal credit card information. The actor has evolved their malware to include rootkits for stealthy installations and has shifted their focus from personal information to cryptocurrency and credit card data. Water Orthrus has been linked to the Scranos campaign reported in 2019.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Education
Aerospace
Manufacturing
Healthcare
Media
Maritime
Information technology
Think tank
Critical infrastructure
Nuclear
Retail
Chemical
Pharmaceutical
Transportation
Hospitality
Gaming
Mining
Legal services
Entertainment

Targeted Countries / Regions

CN
US
TW
JP
DE
IN
GB
KR
RU
UA
SA
AU
IR
PL
FR
TR
PK
VN
IL
CA
ES
KZ
BY
SG
KP
IT
AE
BR
NL
MX
AZ
RO
IQ
EG
SY
NG

AI Analysis

· 1 week ago

Executive Summary

Water Orthrus is a threat actor known for distributing CopperStealer and CopperPhish malware. They primarily target Microsoft 365 users through phishing campaigns to steal credit card information and cryptocurrency data. The group has demonstrated advanced capabilities in evolving their malware, including the use of rootkits for stealthy installations, and has shifted focus from personal data theft to targeting financial information. Water Orthrus has been linked to the Scranos campaign reported in 2019.

Goals & Targeting

Water Orthrus's strategic objectives revolve around financial gain through the theft of credit card information and cryptocurrency assets. Their targeting profile focuses on Microsoft 365 users, indicating a preference for corporate environments and individuals with access to sensitive financial resources. The actor's evolution from personal data theft to focusing on high-value financial information suggests an aim to maximize illicit profits. Their victims are typically individuals or organizations that use Microsoft 365 services, where phishing campaigns can be effectively deployed to steal login credentials and financial data.

Enhanced Description

Water Orthrus is a cyber threat group known for its malicious activities, primarily focusing on stealing sensitive user information through sophisticated phishing campaigns. The group targets Microsoft 365 users, leveraging phishing techniques to distribute their malware, CopperStealer and CopperPhish. Initially targeting personal data, Water Orthrus has evolved to focus on cryptocurrency wallets and credit card details. This shift indicates a strategic pivot toward high-value financial assets. The group's operational capabilities include the use of rootkits, which enable stealthy installation and persistence on victim systems. Their ability to evolve their malware demonstrates a level of technical sophistication, allowing them to stay ahead of traditional detection methods. Water Orthrus has been associated with the Scranos campaign, highlighting their involvement in large-scale cybercriminal operations.

Key Capabilities

  • Phishing with malicious Office documents
  • Rootkit deployment for persistence
  • CopperStealer and CopperPhish malware distribution
  • Stealing credit card information and cryptocurrency assets

MITRE ATT&CK Tactics

Credential Access
Execution
Persistence
Discovery

ATT&CK Techniques

T1560.002
T1553.001
T1566.001
T1547.001

Software / Tooling

CopperStealer
CopperPhish
Rootkit malware

Campaigns & Victims

Water Orthrus has been involved in several campaigns, most notably the Scranos campaign reported in 2019. Their operations typically involve spear-phishing emails with malicious Office attachments or links leading to credential harvesting pages. The group operates with a steady pace, targeting victims over an extended period to maximize their reach and effectiveness. Notable past operations include large-scale phishing campaigns aimed at stealing financial information, underscoring their focus on monetizing stolen data.

IOC Patterns

  • Phishing emails mimicking Microsoft 365 services
  • Malicious Office documents with embedded macros
  • C2 communication via encrypted channels

Recommended Actions

  • Implement multi-factor authentication for Microsoft 365 accounts
  • Monitor for异常登录活动和网络流量异常
  • 教育员工识别钓鱼邮件
  • 定期更新Antivirus software to detect known malware

Suggested Tags

APT
phishing
financial-fraud
malware

Confidence Assessment

The data on Water Orthrus is limited, with a moderate level of confidence in their identified tactics and tools. Further analysis is required to fully understand their operational techniques and the extent of their campaign activity.

ATT&CK Techniques

Collection
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 8 URL 2 Filename 8 SHA-256 Hash 2

References

  1. library.bsafes.com — Cited by web research for: Cozy Bear
  2. www.trendmicro.com — Cited by web research for: Global
  3. misp-galaxy.org — Cited by web research for: Jackal
  4. thehackernews.com — Cited by web research for: CVE-2022-26706

Intel Summary

1

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

Financial Targeting
Phishing
APT
phishing
financial-fraud
malware

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.