Also known as: root access, Moutabal, Baba, a botnet, NOBELIUM, diplomatic entities
OverFlame emerged as a covert operation that targets a broad spectrum of organizations, ranging from energy providers and defense contractors to healthcare facilities and media outlets. Employing sophisticated phishing campaigns, the group delivers trojanized legitimate software which installs persistent backdoors such as PlugX, granting remote control and privileged access. The actor leverages accidental or known firmware vulnerabilities in network devices to expand lateral movement within compromised networks. Once an environment is accessed they deploy ancillary malware—including ransomware, spyware, and cryptojacking tools—enrolling machines into a botnet that serves both DDoS amplification and large‑scale cryptocurrency mining. Operationally, OverFlame coordinates with other pro‑Russian entities (e.g., S16, People’s Cyber Army) to launch synchronized attacks, emphasizing political events or geopolitical tensions. Their modus operandi indicates dual motivations: ideological disruption of target sectors and financial gain through monetization of botnet resources.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
OverFlame is a Russia‑based hacktivist group that blends traditional phishing with trojan‑based backdoor deployments and opportunistic exploitation of network device vulnerabilities. They orchestrate DDoS attacks, cryptomining operations, and ransomware/spyware campaigns primarily against government, critical infrastructure, and financial sectors in Europe and North America. The actor is linked to pro‑Russian threat communities and operates largely through underground forums and encrypted messaging platforms.
Goals & Targeting
The core objective of OverFlame is to inflict operational disruption on critical infrastructures while extracting economic value via cryptomining or ransomware payouts. Target selection reflects a strategy favoring high‑profile public entities—energy, defense, finance—and extends globally with preference for EU and North American jurisdictions that align with current Russian foreign policy objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
OverFlame operates with an adaptive campaign model: short bursts of phishing campaigns that deploy backdoors, followed by scaling botnet activity for DDoS or cryptomining. The group often synchronizes operations with other pro‑Russian actors during politically significant events to amplify perceived impact. Victim profiles skew toward high‑visibility public institutions and large private sectors, while geographic reach spans EU nations, US states, Canada, Israel, and parts of Asia, reflecting a focus on regions sensitive to Russian geopolitical interests.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the core TTPs—phishing, trojanized backdoors, DDoS, and cryptomining—based on multiple correlated reports. Attribution remains uncertain due to overlapping tactics used by other pro‑Russian groups; detailed evidence linking OverFlame to specific incidents is sparse. Future intelligence will need to clarify operational timelines, full tool set breadth, and confirm ideological motivations beyond opportunistic financial gains.
No campaigns linked yet.
No observed data linked yet.
21
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
4
Tactics