Also known as: Cozy Bear, Fancy Bear, BlueBravo, APT29, APT28, Forest Blizzard, Cloaked Ursa, BlueDelta, Ethereal Panda, Carderbee, CVE-2023-38035, Storm-0401, Daggerfly, Bronze Highland, StormBamboo, Nobelium, Midnight Blizzard, The Dukes, SeedWorm, TEMP.Zagros, Static Kitten, APT-C-35, Origami Elephant, APT-C-36, APT43, Emerald Sleet, Sparkling Pisces, Springtail, TA427, Velvet Chollima, APT42, NiceCurl, TameCat, to infiltrate Windows machines, such as VPN services, compromised EdgeOS routers, to hide its tracks, carry out sophisticated attacks, Muddywater, APT36
Water Orthrus is a threat actor known for distributing CopperStealer and CopperPhish malware. They target Microsoft 365 users with phishing campaigns to steal credit card information. The actor has evolved their malware to include rootkits for stealthy installations and has shifted their focus from personal information to cryptocurrency and credit card data. Water Orthrus has been linked to the Scranos campaign reported in 2019.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Water Orthrus is a threat actor known for distributing CopperStealer and CopperPhish malware. They primarily target Microsoft 365 users through phishing campaigns to steal credit card information and cryptocurrency data. The group has demonstrated advanced capabilities in evolving their malware, including the use of rootkits for stealthy installations, and has shifted focus from personal data theft to targeting financial information. Water Orthrus has been linked to the Scranos campaign reported in 2019.
Goals & Targeting
Water Orthrus's strategic objectives revolve around financial gain through the theft of credit card information and cryptocurrency assets. Their targeting profile focuses on Microsoft 365 users, indicating a preference for corporate environments and individuals with access to sensitive financial resources. The actor's evolution from personal data theft to focusing on high-value financial information suggests an aim to maximize illicit profits. Their victims are typically individuals or organizations that use Microsoft 365 services, where phishing campaigns can be effectively deployed to steal login credentials and financial data.
Enhanced Description
Water Orthrus is a cyber threat group known for its malicious activities, primarily focusing on stealing sensitive user information through sophisticated phishing campaigns. The group targets Microsoft 365 users, leveraging phishing techniques to distribute their malware, CopperStealer and CopperPhish. Initially targeting personal data, Water Orthrus has evolved to focus on cryptocurrency wallets and credit card details. This shift indicates a strategic pivot toward high-value financial assets. The group's operational capabilities include the use of rootkits, which enable stealthy installation and persistence on victim systems. Their ability to evolve their malware demonstrates a level of technical sophistication, allowing them to stay ahead of traditional detection methods. Water Orthrus has been associated with the Scranos campaign, highlighting their involvement in large-scale cybercriminal operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Water Orthrus has been involved in several campaigns, most notably the Scranos campaign reported in 2019. Their operations typically involve spear-phishing emails with malicious Office attachments or links leading to credential harvesting pages. The group operates with a steady pace, targeting victims over an extended period to maximize their reach and effectiveness. Notable past operations include large-scale phishing campaigns aimed at stealing financial information, underscoring their focus on monetizing stolen data.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on Water Orthrus is limited, with a moderate level of confidence in their identified tactics and tools. Further analysis is required to fully understand their operational techniques and the extent of their campaign activity.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
1
Tactics