Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Water Makara

Also known as: PINEAPPLE, APT29, Cozy Bear, Storm-2945 ATTACK, RedCurl, used spear-phishing emails, exfiltrate confidential business data, SEO poisoning, SEO Trojans, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Core Werewolf, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Asylum Ambuscade, Guildma, UNC4221, Earth Pret, HoneyMyte, Twill Typhoon, Bloody Wolf, Fancy Bear, RedMike, OPERATOR PANDA, Red Wolf, GOLD BLADE

Description

Water Makara’s campaign portfolio demonstrates a high level of operational sophistication. The actor routinely crafts spear‑phishing emails that appear as official tax documents or legitimate company correspondence, embedding obfuscated JavaScript inside ZIP archives. When an employee opens the attachment, an MSHTA.exe process is triggered, which initiates a payload downloader written in PowerShell; the downloader pulls additional DLLs and configuration files from domain‑generated command-and-control servers. Once installed, the Astaroth banking trojan provides credential theft capabilities and covert data exfiltration. The group also supplements its primary malware by deploying remote access tools such as AnyDesk or Remote Utilities to maintain persistence and facilitate lateral movement across compromised networks. In several campaigns, Water Makara has exploited public zero‑day vulnerabilities (CVE‑2024‑9680, CVE‑2024‑49039) for initial compromise or privilege escalation via undocumented RPC endpoints. To date, the actor’s operations appear largely focused on financial institutions and defense contractors across Latin America, South Asia, and parts of Europe. Their ability to obfuscate scripts, abuse legitimate Windows utilities (mshta.exe), and use domain generation algorithms makes detection challenging without proper endpoint visibility and threat‑intelligence integration.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Healthcare
Telecommunications
Education
Energy
Manufacturing
Critical infrastructure
Media
Pharmaceutical
Transportation
Construction
Retail
Non profit
Hospitality
Aviation
Maritime
Information technology
Food agriculture
Chemical
Mining
Legal services
Utilities
Nuclear
Think tank
Aerospace
Gaming

Targeted Countries / Regions

US
CN
RU
IR
BR
UA
IN
PK
CA
DE
TR
TW
PL
KP
JP
GB
KR
IT
AE
FR
ES
SG
IL
VN
AU
SA
RO
NG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Water Makara is a financially motivated threat actor that delivers the Astaroth banking trojan through sophisticated spear‑phishing campaigns, primarily targeting Latin American and Asian enterprises via obfuscated JavaScript payloads inside malicious ZIP attachments. The group leverages multiple zero‑day CVEs for initial access, employs domain generation algorithms for command‑and‑control, and installs remote access software such as AnyDesk to expand lateral movement. Security teams should proactively block MSHTA.exe execution, enforce MFA, patch the latest CVEs, and monitor outbound traffic for DGA domains while educating users on tax‑document and LNK‑based phishing messages.

Goals & Targeting

Water Makara primarily seeks monetary gain by harvesting banking credentials through the Astaroth trojan while also stealing corporate data for potential resale or future leverage. The actor targets a broad range of public and private sectors—especially finance, defense, healthcare, and utilities—in countries such as Brazil, Pakistan, Russia, China, Iran, and multiple European states. By combining high‑yield targeted phishing with zero‑day exploitation and sophisticated persistence mechanisms, Water Makara aims to maintain long‑term access to high‑value assets. They exhibit a preference for low‑cost delivery vectors—spear‑phishing emails with obfuscated files that exploit widely exposed CVEs—to keep operational complexity manageable while maximizing impact across diverse victim profiles.

Enhanced Description

Key Capabilities

  • Spear‑phishing with obfuscated JavaScript
  • Delivery via malicious ZIP attachments disguised as tax documents
  • Execution through mshta.exe
  • LNK files masquerading as RTF for initial infection
  • PowerShell‑based DLL download and execution
  • Extraction of configuration data from embedded JSON
  • Random domain generation for backup command‑and‑control servers
  • Exploitation of multiple CVEs to gain initial access
  • Zero-click exploitation using zero-day vulnerabilities (CVE-2024-9680, CVE-2024-49039)
  • Sandbox escape via undocumented RPC endpoint to launch hidden PowerShell
  • Automatic download and execution of HTA files and malicious backdoors
  • Installation of remote access tools such as AnyDesk and Remote Utilities
  • Use of JavaScript downloader for further payload delivery
  • Credential theft from browsers using PowerShower backdoor

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Privilege Escalation
Persistence
Credential Access

ATT&CK Techniques

T1059.007
T1204.002
T1059.003
T1106
T1068
T1071.001
T1190
T1189

Software / Tooling

PlugX
Astaroth
GHOSTSPIDER
DEMODEX
SNAPPYBEE
SparrowDoor
CrowDoor
MASOL RAT
Deed RAT
Cobalt Strike
RomCom RAT
VBShower backdoor
PowerShower backdoor
VBCloud implant
AnyDesk
Remote Utilities
WasabiSeed
ScreenShotter
AHK Bot
Resident backdoor
CSharp-Streamer-RAT
Rhadamanthys

Campaigns & Victims

Water Makara’s campaigns follow a recurring pattern of spear‑phishing via seemingly legitimate documents, with ZIP or RTF attachments acting as entry points. The delivery chain typically involves mshta.exe and PowerShell scripts that fetch additional components from DGA hosts and install the Astaroth trojan. Occasionally the actor injects zero‑day exploits into their kits to gain a privilege escalation advantage or to bypass initial security controls in high‑profile targets such as defense contractors. Victim profiles span across many sectors, but there is an evident emphasis on financial institutions and government or defense entities where banking credentials and sensitive data are highly valued. The operational tempo appears steady rather than erratic; after establishing persistence, the group moves laterally using remote desktop utilities while exfiltrating data at a moderate rate. Past operations in Brazil and Pakistan showcase their use of localized phishing materials (tax documents, local government forms) to increase user trust—a tactic that aligns with their observed emphasis on human error exploitation.

IOC Patterns

  • Suspicious obfuscated JavaScript payload
  • ZIP attachment disguised as tax documents
  • Phishing LNK file masquerading as RTF
  • Execution via mshta.exe
  • Domain generation algorithm for C&C
  • DLL downloaded through PowerShell
  • Embedded JSON configuration extraction
  • Zero-day vulnerability exploitation (CVE-2024-9680, CVE-2024-49039)
  • Malicious RTF template exploiting formula editor
  • HTA file download and execution via mshta.exe
  • LNK abuse to trigger mshta.exe
  • JavaScript downloader restricted by IP and time

Recommended Actions

  • Block or filter malicious ZIP attachments in email gateways.
  • Restrict or monitor execution of mshta.exe on endpoints.
  • Implement user training focused on phishing with tax documents and LNK files.
  • Deploy network monitoring to detect domain generation algorithm domains.
  • Apply patches for CVE-2024-9680, CVE-2024-49039 (and other recent CVEs).
  • Use endpoint protection to detect Astaroth, PlugX, GHOSTSPIDER, Deed RAT, RomCom RAT and related malware.
  • Implement application whitelisting; block mshta.exe where feasible.
  • Deploy multi‑factor authentication to protect remote access tools and reduce credential theft impact.
  • Use email filtering solutions that scan attachments for malicious behaviors such as Jscript downloads or RTF formula exploits.
  • Enable EDR with rules for suspicious PowerShell activity and hidden processes.
  • Educate users on phishing indicators, especially zip archives and official-looking documents.

Suggested Tags

spear-phishing
JavaScript obfuscation
malicious ZIP
LNK phishing
mshta exploitation
domain generation algorithm
zero-click exploits
CVE-2024-9680
CVE-2024-49039
credential theft
remote access tools
financial data exfiltration

Confidence Assessment

The analysis is based on multiple publicly available reports and observed IOC samples, providing a moderate level of confidence in the actor’s tactics, techniques, and motivations. Attribution to the Water Makara alias remains ambiguous because of overlapping aliases such as Cozy Bear or Fancy Bear; however, the specific combination of Astaroth trojan delivery via encrypted ZIP attachments with mshta.exe execution is strongly correlated to recent campaigns in Latin America. Gaps exist regarding the exact timeline of deployments, full attack matrix coverage, and confirmation of all zero‑day exploit uses. The data does not conclusively establish Water Makara as distinct from other groups that use Astaroth, so additional threat intelligence (e.g., threat actor linking, shared infrastructure) is needed for definitive attribution.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 19 Filename 1

References

  1. www.trendmicro.com — Cited by web research for: RedCurl
  2. www.trendmicro.com — Cited by web research for: SEO poisoning
  3. ics-cert.kaspersky.com — Cited by web research for: APT-C-35
  4. www.hackmageddon.com — Cited by web research for: Earth Pret
  5. threatintel.cc — Cited by web research for: Bloody Wolf
  6. https://unit42.paloaltonetworks.com — Cited by AI analysis.
  7. https://research.checkpoint.com — Cited by AI analysis.
  8. https://securelist.com — Cited by AI analysis.
  9. https://www.fortinet.com — Cited by AI analysis.
  10. https://www.bleepingcomputer.com — Cited by AI analysis.

Intel Summary

9

Techniques

60

Tools

0

Campaigns

38

IOCs

0

Observed Data

4

Tactics

Tags

Financial Targeting
Phishing
spear-phishing
JavaScript obfuscation
malicious ZIP
LNK phishing
mshta exploitation
domain generation algorithm
zero-click exploits
CVE-2024-9680
CVE-2024-49039
credential theft
remote access tools
financial data exfiltration

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.