Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Markopolo

Also known as: services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code

Description

Markopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog to legitimize their malicious activities. Markopolo has been linked to a credential-harvesting operation and is agile in pivoting to new scams when detected. The actor leverages shared hosting and C2 infrastructure for their malicious builds.

Goals & Targeting

Targeted Sectors

Financial services
Media
Defense
Manufacturing
Energy
Government
Aerospace
Aviation
Information technology

Targeted Countries / Regions

IR
CN
JP
SA

AI Analysis

· 1 week ago

Executive Summary

Markopolo is a threat actor targeting cryptocurrency users through fake apps, social media, and phishing campaigns. Their operations focus on financial gain via credential theft and scams, making them a significant concern for individuals and organizations in tech and finance sectors.

Goals & Targeting

Markopolo's main goals are financial, achieved through credential harvesting and cryptocurrency scams. They target individuals and organizations in the technology sector who may use or promote cryptocurrency platforms. The actor is also observed targeting financial sectors due to the high value of personal financial information.

Enhanced Description

Markopolo operates by creating fake cryptocurrency applications like Vortax to deceive users. They use social media and blogs to legitimize their malicious activities, distributing phishing emails with malicious links that lead users to download these apps. The threat actor is known for quickly adapting their tactics when detected, which has allowed them to maintain activity despite attempts to disrupt their operations. Markopolo leverages shared hosting services and command-and-control (C2) infrastructure to maintain their campaigns. Their targeting of cryptocurrency users suggests a primary focus on financial gain through large-scale scams.

Key Capabilities

  • Spear-phishing with malicious links
  • Fake cryptocurrency apps for credential harvesting
  • Shared hosting infrastructure for C2 operations

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Discovery

ATT&CK Techniques

T1566
T1078
T1059
T1543
T1562

Software / Tooling

Custom Malware

Campaigns & Victims

Markopolo campaigns exhibit agility, frequently pivoting to new schemes upon detection. They primarily target ordinary users and cryptocurrency enthusiasts through social media platforms. A notable operation involved a fake giveaway offer that led victims to share their credentials with the threat actor.

IOC Patterns

  • Spear-phishing emails with malicious links
  • Fake application downloads
  • Shared hosting domains for C2
  • Command and control infrastructure

Recommended Actions

  • Implement robust anti-phishing measures
  • Monitor for fake application distribution attempts
  • Enforce multi-factor authentication (MFA)
  • Use IOC filtering techniques to block known threat patterns

Suggested Tags

Scam/Financial Fraud
Malware/C2
Social Engineering
Crypto
Tech Sector

Confidence Assessment

The data on Markopolo is sufficient for identification but limited in depth. Specific targets beyond cryptocurrency users are unclear. Their exact targeting methodology and precise TTPs require further analysis.

ATT&CK Techniques

Exfiltration
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 11 Domain 5 SHA-256 Hash 2 IPv4 Address 1 MD5 Hash 1

References

  1. attack.mitre.org — Cited by web research for: services
  2. www.recordedfuture.com — Cited by web research for: Telegram
  3. attack.mitre.org — Cited by web research for: MSBuild
  4. www.paloaltonetworks.com — Cited by web research for: package-lock.json
  5. www.thedailystar.net — Cited by web research for: Japan

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Financial Targeting
Backdoor / C2
Scam/Financial Fraud
Malware/C2
Social Engineering
Crypto
Tech Sector

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.