Also known as: cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, 2023, is deeply troubling, 560048, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm
TOXCAR CYBER TEAM operates with a high degree of sophistication, employing a blend of phishing, exploitation, and advanced malware techniques to infiltrate target organizations—particularly those in government, defense, energy, finance, and technology. Their initial access vectors frequently involve spear‑phishing attachments embedded in malicious Microsoft Word documents, which trigger DLL side‑loading attacks that bypass endpoint protections. Once inside a network, the group escalates privileges using zero‑day vulnerabilities (notably CVE-2015-1701) and deploys downloaders such as IRONHALO or backdoors like ELMER to expand their foothold. They also leverage commercial tools—including Cobalt Strike, Havoc, and the PlugX family of RATs—to conduct reconnaissance, maintain persistence, and orchestrate lateral movement. Data exfiltration is carried out via a combination of standard network channels and custom Exfiltration Over Uncommonly Used Ports (T1220), often accompanied by data compression and encryption to avoid detection. The group demonstrates an ability to rapidly pivot between toolsets, adopting new backdoors or malware variants on short notice, which complicates attribution and mitigations. In addition to their espionage campaigns, TOXCAR CYBER TEAM has been linked to commercial ransomware markets, claiming involvement in MasterCard data leaks and releasing source code for the Elusive Stealer. These dual threats underscore their intent to monetize both intelligence and destructive malware assets.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TOXCAR CYBER TEAM, also referred to as APT3/Buckeye and Grayling, is a state‑backed espionage group that targets a wide array of sectors worldwide. They use sophisticated phishing campaigns, DLL side‑loading, zero‑day CVE exploitation, and commercially available penetration tools such as Cobalt Strike and Havoc to gain initial access and establish persistence. Their operations consistently result in large‑scale data exfiltration from governmental, critical infrastructure, and private sector victims.
Goals & Targeting
The primary strategic objective of TOXCAR CYBER TEAM is geopolitical espionage: harvesting sensitive information from government agencies, defense contractors, critical infrastructure operators, and high‑value private sector enterprises across more than thirty countries. Their targeting matrix spans public and commercial sectors, with a particular focus on energy, aerospace, telecommunications, healthcare, and finance, enabling intelligence gathering that informs state policy, economic advantage, and cyber warfare capabilities.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TOXCAR CYBER TEAM conducts campaigns that blend spear‑phishing, watering holes, and zero‑day exploitation to breach high‑profile targets. Their operations are characterized by swift transitions between malware families, enabling them to maintain low profiles while scaling data collection volumes. Victims span governmental ministries, defense contractors, financial institutions, media outlets, and energy firms in the US, EU, Asia, and Africa. Notable incidents include a Mastercard data leak alleged by the group, distribution of an undetectable ransomware variant, and public release of Elusive Stealer source code.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence suggests a credible attribution to TOXCAR CYBER TEAM with strong indications of state sponsorship focused on espionage. However, alias overlap and inconsistent reports introduce uncertainty about the group's true origin and full operational scope. Key gaps remain in the exact timeline of activities, the breadth of their toolset evolution, and definitive evidence linking them to all cited incidents such as the MasterCard leak.
No campaigns linked yet.
No observed data linked yet.
5
Techniques
53
Tools
0
Campaigns
35
IOCs
0
Observed Data
4
Tactics