Also known as: LandUpdate808, tracking, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down
Tstark is characterized by a diverse set of intrusion vectors that blend social engineering with technical exploitation. The actor leverages phishing campaigns delivering malicious JavaScript attachments or disguised as legitimate browser updates (SocGholish) to gain initial foothold, especially in energy, oil‑and‑gas, and legal sectors across the US and Europe. Once inside, Tstark deploys custom loaders—most notably MintsLoader—to facilitate infection chaining, download additional malware such as MintsLoader-based backdoors, or install ransomware families like Royal Ransomware (also known as BlackCat) for financial gain. Beyond initial access, Tstark demonstrates advanced post‑exploitation proficiency. It exploits the CVE-2020-15069 buffer overflow in bookmark handling and a WebAssembly vulnerability to elevate privileges (T1203) or inject hostile iframes (T1189). The actor also utilizes VPN-based lateral movement, evident in intermittent IPs across Hong Kong and Chengdu, and exfiltrates data through web services or alternate protocols (T1567, T1048), often staging stolen information on temporary domains such as Temp.Zagros. The group's strategic use of ransomware is coupled with double‑extortion tactics: encrypting data while simultaneously threatening with public release. Their toolkit includes well‑known backdoors (AsyncRAT, Mythic), Cobalt Strike frameworks for command and control, and PowerShell scripts to orchestrate persistence. This combination of zero‑day exploitation, credential compromise via phishing or brute force, and payload delivery reflects a sophisticated threat actor that blends financially driven motives with cyber espionage capabilities. Tstark's operational tempo remains high, deploying multiple campaign waves through emerging delivery channels such as compromised websites and paid-to-play distribution networks. While the full timeline of the actor is not fully established, evidence from 2024–2025 indicates a sustained presence across North America, Europe, Asia, and the Middle East—targeting both public sector organizations and high‑value private firms.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Tstark—also known as LandUpdate808, Royal Ransomware and other aliases—is a financially motivated threat actor targeting a wide spectrum of sectors, from finance and healthcare to critical infrastructure and defense. The group employs layered tactics including phishing, exploitation of browser and VPN vulnerabilities, and custom loaders such as MintsLoader to deliver ransomware payloads. Recent activity shows the actor using sophisticated delivery mechanisms—including web‑assembly exploits and temporary C2 domains—to bypass defenses and extend lateral movement across enterprises worldwide.
Goals & Targeting
Tstark’s strategic objectives appear to be purely financial in the short term, primarily through ransomware payouts and double‑extortion. However, by targeting critical sectors such as defense, telecom, and energy, they also acquire sensitive industrial data that could support future corporate espionage operations or offer leverage for negotiating higher ransom amounts. The actor focuses on countries with robust economies—US, UK, Germany—and regions undergoing heightened geopolitical tensions (Ukraine, Russia, Iran) to maximize both monetary value and access to politically significant information. Typical victims are mid‑to‑large enterprises with complex legacy systems, often lacking rigorous patch management or segmentation, which allow the group to exploit known vulnerabilities like CVE-2020-15069 and insecure VPN configurations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operational analysis indicates that Tstark, likely synonymous with TAG‑124/LandUpdate808, carries out repeated ransomware campaigns across multiple continents. The group’s modus operandi often starts with phishing emails or compromised update prompts, followed by the installation of a lightweight loader (MintsLoader) which then fetches a second‑stage payload—commonly a backdoor or ransomware binary. Tstark has been observed shifting between VPN and remote service exploitation as a means of persistence, maintaining a high operational tempo with frequent new indicators disseminated via temporary domains. Their recent focus on exploiting the CVE-2020‑15069 vulnerability demonstrates an ability to rapidly pivot to newly disclosed weaknesses to expand their attack surface.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment relies on a combination of limited primary evidence from the actor’s description and broader industry reports linking similar aliases (LandUpdate808, TAG-124) with known loaders (MintsLoader). While core attributes such as financial motive, phishing delivery, and ransomware deployment are well supported by external sources (e.g., Unit42 & Insikt Group analyses), specific technical details—like exact use of CVE‑2020‑15069 and WebAssembly exploitation—are derived from a single report and lack corroboration. Consequently confidence is moderate; additional up‑to‑date internal telemetry or incident reports would increase certainty about the actor’s full capabilities and current operations.
No campaigns linked yet.
No observed data linked yet.
18
Techniques
42
Tools
0
Campaigns
29
IOCs
0
Observed Data
8
Tactics