Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TOXCAR CYBER TEAM

Also known as: cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, 2023, is deeply troubling, 560048, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm

Description

TOXCAR CYBER TEAM operates with a high degree of sophistication, employing a blend of phishing, exploitation, and advanced malware techniques to infiltrate target organizations—particularly those in government, defense, energy, finance, and technology. Their initial access vectors frequently involve spear‑phishing attachments embedded in malicious Microsoft Word documents, which trigger DLL side‑loading attacks that bypass endpoint protections. Once inside a network, the group escalates privileges using zero‑day vulnerabilities (notably CVE-2015-1701) and deploys downloaders such as IRONHALO or backdoors like ELMER to expand their foothold. They also leverage commercial tools—including Cobalt Strike, Havoc, and the PlugX family of RATs—to conduct reconnaissance, maintain persistence, and orchestrate lateral movement. Data exfiltration is carried out via a combination of standard network channels and custom Exfiltration Over Uncommonly Used Ports (T1220), often accompanied by data compression and encryption to avoid detection. The group demonstrates an ability to rapidly pivot between toolsets, adopting new backdoors or malware variants on short notice, which complicates attribution and mitigations. In addition to their espionage campaigns, TOXCAR CYBER TEAM has been linked to commercial ransomware markets, claiming involvement in MasterCard data leaks and releasing source code for the Elusive Stealer. These dual threats underscore their intent to monetize both intelligence and destructive malware assets.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Non profit
Telecommunications
Energy
Aerospace
Manufacturing
Information technology
Media
Healthcare
Education
Pharmaceutical
Transportation
Maritime
Mining
Retail
Think tank
Food agriculture
Critical infrastructure
Chemical
Hospitality
Entertainment
Construction
Utilities
Nuclear
Gaming
Legal services
Aviation
Oil gas

Targeted Countries / Regions

IN
US
CN
GB
JP
KR
DE
AU
RU
FR
TW
IR
IL
CA
SA
PK
TR
KZ
VN
UA
SG
BR
ES
PL
NL
IT
AE
BY
IQ
MX
RO
SY
AZ
EG
KP
LB

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

TOXCAR CYBER TEAM, also referred to as APT3/Buckeye and Grayling, is a state‑backed espionage group that targets a wide array of sectors worldwide. They use sophisticated phishing campaigns, DLL side‑loading, zero‑day CVE exploitation, and commercially available penetration tools such as Cobalt Strike and Havoc to gain initial access and establish persistence. Their operations consistently result in large‑scale data exfiltration from governmental, critical infrastructure, and private sector victims.

Goals & Targeting

The primary strategic objective of TOXCAR CYBER TEAM is geopolitical espionage: harvesting sensitive information from government agencies, defense contractors, critical infrastructure operators, and high‑value private sector enterprises across more than thirty countries. Their targeting matrix spans public and commercial sectors, with a particular focus on energy, aerospace, telecommunications, healthcare, and finance, enabling intelligence gathering that informs state policy, economic advantage, and cyber warfare capabilities.

Enhanced Description

Key Capabilities

  • DLL side-loading for credential theft
  • Spear‑phishing via malicious Word attachments
  • Zero‑day CVE exploitation (e.g., CVE-2015-1701)
  • Downloader backdoors such as IRONHALO and ELMER
  • Use of commercial threat tools (Cobalt Strike, Havoc)
  • Watering‑hole attacks against targeted organizations
  • Rapid toolset switching to maintain persistence and stealth
  • Mass data exfiltration using diverse channels

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Persistence
Collection
Exfiltration

ATT&CK Techniques

T1566.001
T1220
T1068
T1204
T1189

Software / Tooling

Cobalt Strike
Havoc
PlugX
Ghost RAT
CHINACHOPPER
IRONHALO
ELMER
MiniDuke
CosmicDuke
OnionDuke
CozyDuke
SeaDuke
HammerDuke
PinchDuke
GeminiDuke
Crimson
Anchor

Campaigns & Victims

TOXCAR CYBER TEAM conducts campaigns that blend spear‑phishing, watering holes, and zero‑day exploitation to breach high‑profile targets. Their operations are characterized by swift transitions between malware families, enabling them to maintain low profiles while scaling data collection volumes. Victims span governmental ministries, defense contractors, financial institutions, media outlets, and energy firms in the US, EU, Asia, and Africa. Notable incidents include a Mastercard data leak alleged by the group, distribution of an undetectable ransomware variant, and public release of Elusive Stealer source code.

IOC Patterns

  • DLL side-loading
  • Spear‑phishing attachments
  • Zero‑day vulnerability exploitation (CVE-2015-1701)
  • Privilege escalation via local CVEs
  • Watering‑hole attacks
  • Mass exfiltration patterns

Recommended Actions

  • Patch and remediate known vulnerabilities, especially CVE-2015-1701 and other relevant CVEs.
  • Block or filter suspicious Word attachments containing macros or exploit templates.
  • Monitor DLL load paths for side‑loading indicators and block anomalous load operations.
  • Detect and quarantine the use of known threat actor tools (Cobalt Strike, Havoc) on the network.
  • Deploy endpoint protection that flags downloader binaries such as IRONHALO and obfuscated backdoors like ELMER.
  • Implement multi‑factor authentication to mitigate credential theft via phishing campaigns.
  • Deploy intrusion detection/prevention systems tuned to detect known malicious toolsets and anomalous exfiltration behavior.
  • Segment networks, enforce least‑privilege policies, and restrict lateral movement paths.

Suggested Tags

APT3
Buckeye
Grayling
Spearphishing_Attachment
DLL_Side_Loading
Privilege_Escalation
Use-after-free_Vulnerability
CVE-2015-1701
WateringHole
Ransomware
Data_Exfiltration

Confidence Assessment

The available intelligence suggests a credible attribution to TOXCAR CYBER TEAM with strong indications of state sponsorship focused on espionage. However, alias overlap and inconsistent reports introduce uncertainty about the group's true origin and full operational scope. Key gaps remain in the exact timeline of activities, the breadth of their toolset evolution, and definitive evidence linking them to all cited incidents such as the MasterCard leak.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 19 Email Address 1

Intel Summary

5

Techniques

53

Tools

0

Campaigns

35

IOCs

0

Observed Data

4

Tactics

Tags

Ransomware
Data Exfiltration
APT
Data Theft
Financial Sector
Cyber Espionage
APT3
Buckeye
Grayling
Spearphishing_Attachment
DLL_Side_Loading
Privilege_Escalation
Use-after-free_Vulnerability
CVE-2015-1701
WateringHole
Data_Exfiltration

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.