Also known as: services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code
Markopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog to legitimize their malicious activities. Markopolo has been linked to a credential-harvesting operation and is agile in pivoting to new scams when detected. The actor leverages shared hosting and C2 infrastructure for their malicious builds.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Markopolo is a threat actor targeting cryptocurrency users through fake apps, social media, and phishing campaigns. Their operations focus on financial gain via credential theft and scams, making them a significant concern for individuals and organizations in tech and finance sectors.
Goals & Targeting
Markopolo's main goals are financial, achieved through credential harvesting and cryptocurrency scams. They target individuals and organizations in the technology sector who may use or promote cryptocurrency platforms. The actor is also observed targeting financial sectors due to the high value of personal financial information.
Enhanced Description
Markopolo operates by creating fake cryptocurrency applications like Vortax to deceive users. They use social media and blogs to legitimize their malicious activities, distributing phishing emails with malicious links that lead users to download these apps. The threat actor is known for quickly adapting their tactics when detected, which has allowed them to maintain activity despite attempts to disrupt their operations. Markopolo leverages shared hosting services and command-and-control (C2) infrastructure to maintain their campaigns. Their targeting of cryptocurrency users suggests a primary focus on financial gain through large-scale scams.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Markopolo campaigns exhibit agility, frequently pivoting to new schemes upon detection. They primarily target ordinary users and cryptocurrency enthusiasts through social media platforms. A notable operation involved a fake giveaway offer that led victims to share their credentials with the threat actor.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on Markopolo is sufficient for identification but limited in depth. Specific targets beyond cryptocurrency users are unclear. Their exact targeting methodology and precise TTPs require further analysis.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics