Also known as: PINEAPPLE, APT29, Cozy Bear, Storm-2945 ATTACK, RedCurl, used spear-phishing emails, exfiltrate confidential business data, SEO poisoning, SEO Trojans, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Core Werewolf, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Asylum Ambuscade, Guildma, UNC4221, Earth Pret, HoneyMyte, Twill Typhoon, Bloody Wolf, Fancy Bear, RedMike, OPERATOR PANDA, Red Wolf, GOLD BLADE
Water Makara’s campaign portfolio demonstrates a high level of operational sophistication. The actor routinely crafts spear‑phishing emails that appear as official tax documents or legitimate company correspondence, embedding obfuscated JavaScript inside ZIP archives. When an employee opens the attachment, an MSHTA.exe process is triggered, which initiates a payload downloader written in PowerShell; the downloader pulls additional DLLs and configuration files from domain‑generated command-and-control servers. Once installed, the Astaroth banking trojan provides credential theft capabilities and covert data exfiltration. The group also supplements its primary malware by deploying remote access tools such as AnyDesk or Remote Utilities to maintain persistence and facilitate lateral movement across compromised networks. In several campaigns, Water Makara has exploited public zero‑day vulnerabilities (CVE‑2024‑9680, CVE‑2024‑49039) for initial compromise or privilege escalation via undocumented RPC endpoints. To date, the actor’s operations appear largely focused on financial institutions and defense contractors across Latin America, South Asia, and parts of Europe. Their ability to obfuscate scripts, abuse legitimate Windows utilities (mshta.exe), and use domain generation algorithms makes detection challenging without proper endpoint visibility and threat‑intelligence integration.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Water Makara is a financially motivated threat actor that delivers the Astaroth banking trojan through sophisticated spear‑phishing campaigns, primarily targeting Latin American and Asian enterprises via obfuscated JavaScript payloads inside malicious ZIP attachments. The group leverages multiple zero‑day CVEs for initial access, employs domain generation algorithms for command‑and‑control, and installs remote access software such as AnyDesk to expand lateral movement. Security teams should proactively block MSHTA.exe execution, enforce MFA, patch the latest CVEs, and monitor outbound traffic for DGA domains while educating users on tax‑document and LNK‑based phishing messages.
Goals & Targeting
Water Makara primarily seeks monetary gain by harvesting banking credentials through the Astaroth trojan while also stealing corporate data for potential resale or future leverage. The actor targets a broad range of public and private sectors—especially finance, defense, healthcare, and utilities—in countries such as Brazil, Pakistan, Russia, China, Iran, and multiple European states. By combining high‑yield targeted phishing with zero‑day exploitation and sophisticated persistence mechanisms, Water Makara aims to maintain long‑term access to high‑value assets. They exhibit a preference for low‑cost delivery vectors—spear‑phishing emails with obfuscated files that exploit widely exposed CVEs—to keep operational complexity manageable while maximizing impact across diverse victim profiles.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Water Makara’s campaigns follow a recurring pattern of spear‑phishing via seemingly legitimate documents, with ZIP or RTF attachments acting as entry points. The delivery chain typically involves mshta.exe and PowerShell scripts that fetch additional components from DGA hosts and install the Astaroth trojan. Occasionally the actor injects zero‑day exploits into their kits to gain a privilege escalation advantage or to bypass initial security controls in high‑profile targets such as defense contractors. Victim profiles span across many sectors, but there is an evident emphasis on financial institutions and government or defense entities where banking credentials and sensitive data are highly valued. The operational tempo appears steady rather than erratic; after establishing persistence, the group moves laterally using remote desktop utilities while exfiltrating data at a moderate rate. Past operations in Brazil and Pakistan showcase their use of localized phishing materials (tax documents, local government forms) to increase user trust—a tactic that aligns with their observed emphasis on human error exploitation.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on multiple publicly available reports and observed IOC samples, providing a moderate level of confidence in the actor’s tactics, techniques, and motivations. Attribution to the Water Makara alias remains ambiguous because of overlapping aliases such as Cozy Bear or Fancy Bear; however, the specific combination of Astaroth trojan delivery via encrypted ZIP attachments with mshta.exe execution is strongly correlated to recent campaigns in Latin America. Gaps exist regarding the exact timeline of deployments, full attack matrix coverage, and confirmation of all zero‑day exploit uses. The data does not conclusively establish Water Makara as distinct from other groups that use Astaroth, so additional threat intelligence (e.g., threat actor linking, shared infrastructure) is needed for definitive attribution.
No campaigns linked yet.
No observed data linked yet.
9
Techniques
60
Tools
0
Campaigns
38
IOCs
0
Observed Data
4
Tactics