Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors OverFlame

Also known as: root access, Moutabal, Baba, a botnet, NOBELIUM, diplomatic entities

Description

OverFlame emerged as a covert operation that targets a broad spectrum of organizations, ranging from energy providers and defense contractors to healthcare facilities and media outlets. Employing sophisticated phishing campaigns, the group delivers trojanized legitimate software which installs persistent backdoors such as PlugX, granting remote control and privileged access. The actor leverages accidental or known firmware vulnerabilities in network devices to expand lateral movement within compromised networks. Once an environment is accessed they deploy ancillary malware—including ransomware, spyware, and cryptojacking tools—enrolling machines into a botnet that serves both DDoS amplification and large‑scale cryptocurrency mining. Operationally, OverFlame coordinates with other pro‑Russian entities (e.g., S16, People’s Cyber Army) to launch synchronized attacks, emphasizing political events or geopolitical tensions. Their modus operandi indicates dual motivations: ideological disruption of target sectors and financial gain through monetization of botnet resources.

Goals & Targeting

Targeted Sectors

Energy
Nuclear
Financial services
Critical infrastructure
Defense
Manufacturing
Utilities
Government
Healthcare
Media
Oil gas
Non profit
Transportation

Targeted Countries / Regions

RU
UA
FR
US
IL
IR
CN
GB
PL
ES
IT
KP
CA
SA
DE
KR
JP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 4 hours ago

Executive Summary

OverFlame is a Russia‑based hacktivist group that blends traditional phishing with trojan‑based backdoor deployments and opportunistic exploitation of network device vulnerabilities. They orchestrate DDoS attacks, cryptomining operations, and ransomware/spyware campaigns primarily against government, critical infrastructure, and financial sectors in Europe and North America. The actor is linked to pro‑Russian threat communities and operates largely through underground forums and encrypted messaging platforms.

Goals & Targeting

The core objective of OverFlame is to inflict operational disruption on critical infrastructures while extracting economic value via cryptomining or ransomware payouts. Target selection reflects a strategy favoring high‑profile public entities—energy, defense, finance—and extends globally with preference for EU and North American jurisdictions that align with current Russian foreign policy objectives.

Enhanced Description

Key Capabilities

  • Phishing and social engineering to obtain credentials
  • Installation of trojans masquerading as legitimate software leading to backdoor creation
  • Exploitation of network devices for remote access via embedded backdoors
  • Use of known malware families (e.g., PlugX) for persistence
  • Gain super‑user access via backdoors
  • Deploy and maintain remote control via botnets
  • Launch distributed denial‑of‑service attacks
  • Conduct cryptomining operations on compromised systems
  • Install spyware or ransomware on victim machines

MITRE ATT&CK Tactics

Initial Access
Persistence
Privilege Escalation
Command & Control
Impact

ATT&CK Techniques

T1592
T1590
T1566.001
T1204.001

Software / Tooling

PlugX
Emotet
Stuxnet
RansomHub
NotPetya
Havex RAT
Ghost RAT
Metasploit
Dark
Nexus
Singularity
Leverage
Guard
Atmosphere
DragonForce
Global
Globe
Handala
Meow
STOP
Backdoor malware
Keyloggers
Legitimate Software
Telegram
GitHub

Campaigns & Victims

OverFlame operates with an adaptive campaign model: short bursts of phishing campaigns that deploy backdoors, followed by scaling botnet activity for DDoS or cryptomining. The group often synchronizes operations with other pro‑Russian actors during politically significant events to amplify perceived impact. Victim profiles skew toward high‑visibility public institutions and large private sectors, while geographic reach spans EU nations, US states, Canada, Israel, and parts of Asia, reflecting a focus on regions sensitive to Russian geopolitical interests.

IOC Patterns

  • domain
  • file
  • email
  • ip-v4
  • malicious backdoor installation
  • phishing emails containing lure attachments or links
  • trojanized legitimate software

Recommended Actions

  • Deploy endpoint protection that detects RAT behavior such as PlugX and other key trojans
  • Implement robust email filtering, anti‑phishing controls, and user training programs to surface phishing campaigns
  • Apply timely patches for known vulnerabilities in network device firmware and software
  • Block malicious domains and IP addresses identified as command & control infrastructure
  • Monitor for anomalous outbound traffic typical of botnet activity or cryptojacking
  • Restrict privileged account usage with multi‑factor authentication
  • Isolate compromised systems promptly to prevent lateral spread

Suggested Tags

overflame
russian hacktivist
financial-gain
backdoor
phishing
remote access trojan
plugx
botnet
ddos
cryptojacking
exploit

Confidence Assessment

Moderate confidence in the core TTPs—phishing, trojanized backdoors, DDoS, and cryptomining—based on multiple correlated reports. Attribution remains uncertain due to overlapping tactics used by other pro‑Russian groups; detailed evidence linking OverFlame to specific incidents is sparse. Future intelligence will need to clarify operational timelines, full tool set breadth, and confirm ideological motivations beyond opportunistic financial gains.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.malwarebytes.com — Cited by web research for: root access
  2. www.resecurity.com — Cited by web research for: NOBELIUM
  3. www.forescout.com — Cited by web research for: T0821
  4. www.sentinelone.com — Cited by web research for: Singularity
  5. pmc.ncbi.nlm.nih.gov — Cited by web research for: Atmosphere
  6. https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf — Cited by AI analysis.
  7. https://malpedia.caad.fkie.fraunhofer.de/details/win.plugx — Cited by AI analysis.

Intel Summary

21

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

4

Tactics

Tags

Critical Infrastructure
DDoS
Government Targeting
Hacktivism
overflame
russian hacktivist
financial-gain
backdoor
phishing
remote access trojan
plugx
botnet
ddos
cryptojacking
exploit

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.