Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Tstark

Also known as: LandUpdate808, tracking, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down

Description

Tstark is characterized by a diverse set of intrusion vectors that blend social engineering with technical exploitation. The actor leverages phishing campaigns delivering malicious JavaScript attachments or disguised as legitimate browser updates (SocGholish) to gain initial foothold, especially in energy, oil‑and‑gas, and legal sectors across the US and Europe. Once inside, Tstark deploys custom loaders—most notably MintsLoader—to facilitate infection chaining, download additional malware such as MintsLoader-based backdoors, or install ransomware families like Royal Ransomware (also known as BlackCat) for financial gain. Beyond initial access, Tstark demonstrates advanced post‑exploitation proficiency. It exploits the CVE-2020-15069 buffer overflow in bookmark handling and a WebAssembly vulnerability to elevate privileges (T1203) or inject hostile iframes (T1189). The actor also utilizes VPN-based lateral movement, evident in intermittent IPs across Hong Kong and Chengdu, and exfiltrates data through web services or alternate protocols (T1567, T1048), often staging stolen information on temporary domains such as Temp.Zagros. The group's strategic use of ransomware is coupled with double‑extortion tactics: encrypting data while simultaneously threatening with public release. Their toolkit includes well‑known backdoors (AsyncRAT, Mythic), Cobalt Strike frameworks for command and control, and PowerShell scripts to orchestrate persistence. This combination of zero‑day exploitation, credential compromise via phishing or brute force, and payload delivery reflects a sophisticated threat actor that blends financially driven motives with cyber espionage capabilities. Tstark's operational tempo remains high, deploying multiple campaign waves through emerging delivery channels such as compromised websites and paid-to-play distribution networks. While the full timeline of the actor is not fully established, evidence from 2024–2025 indicates a sustained presence across North America, Europe, Asia, and the Middle East—targeting both public sector organizations and high‑value private firms.

Goals & Targeting

Targeted Sectors

Financial services
Healthcare
Government
Education
Telecommunications
Defense
Critical infrastructure
Manufacturing
Retail
Energy
Media
Food agriculture
Non profit
Information technology
Hospitality
Mining
Oil gas
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Construction
Transportation

Targeted Countries / Regions

UA
CN
RU
IN
GB
US
DE
KP
IR
IT
PK
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Tstark—also known as LandUpdate808, Royal Ransomware and other aliases—is a financially motivated threat actor targeting a wide spectrum of sectors, from finance and healthcare to critical infrastructure and defense. The group employs layered tactics including phishing, exploitation of browser and VPN vulnerabilities, and custom loaders such as MintsLoader to deliver ransomware payloads. Recent activity shows the actor using sophisticated delivery mechanisms—including web‑assembly exploits and temporary C2 domains—to bypass defenses and extend lateral movement across enterprises worldwide.

Goals & Targeting

Tstark’s strategic objectives appear to be purely financial in the short term, primarily through ransomware payouts and double‑extortion. However, by targeting critical sectors such as defense, telecom, and energy, they also acquire sensitive industrial data that could support future corporate espionage operations or offer leverage for negotiating higher ransom amounts. The actor focuses on countries with robust economies—US, UK, Germany—and regions undergoing heightened geopolitical tensions (Ukraine, Russia, Iran) to maximize both monetary value and access to politically significant information. Typical victims are mid‑to‑large enterprises with complex legacy systems, often lacking rigorous patch management or segmentation, which allow the group to exploit known vulnerabilities like CVE-2020-15069 and insecure VPN configurations.

Enhanced Description

Key Capabilities

  • Exploiting browser and VPN zero‑day vulnerabilities
  • Phishing delivery of JavaScript attachments and fake web updates
  • Use of custom loaders (MintsLoader) for lateral movement
  • Deployment of ransomware families (Royal Ransomware, BlackCat) with double‑extortion tactics
  • Command & Control via Cobalt Strike and PowerShell scripts
  • Data exfiltration through web services or alternative protocols
  • Credential theft via brute‑force and phishing

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control
Impact

ATT&CK Techniques

T1059.001
T1059.003
T1060
T1071.002
T1140
T1189
T1203
T1133
T1190
T1168
T1566.001
T1567.001
T1048
T1486

Software / Tooling

MintsLoader
AsyncRAT
Mythic
Cobalt Strike
PowerShell
TrickBot
BlackCat (Royal Ransomware)
SocGholish
HELLOKITTY
GrandAgent (GrimAgent)
Disco

Campaigns & Victims

Operational analysis indicates that Tstark, likely synonymous with TAG‑124/LandUpdate808, carries out repeated ransomware campaigns across multiple continents. The group’s modus operandi often starts with phishing emails or compromised update prompts, followed by the installation of a lightweight loader (MintsLoader) which then fetches a second‑stage payload—commonly a backdoor or ransomware binary. Tstark has been observed shifting between VPN and remote service exploitation as a means of persistence, maintaining a high operational tempo with frequent new indicators disseminated via temporary domains. Their recent focus on exploiting the CVE-2020‑15069 vulnerability demonstrates an ability to rapidly pivot to newly disclosed weaknesses to expand their attack surface.

IOC Patterns

  • Spear-phishing emails containing malicious JavaScript attachments
  • Compromised website impersonating browser update prompts (SocGholish)
  • Phishing campaigns distributed via Italy’s PEC certified email system
  • Use of temporary or fast‑flux domains such as Temp.Zagros and TEMP.Akapav for command-and-control or staging
  • Upload of malicious files like update.js to staging servers
  • VPN misconfigurations exploited across Hong Kong and Chengdu IP ranges

Recommended Actions

  • Patch browsers and VPN appliances promptly, particularly addressing CVE‑2020–15069 and WebAssembly related bugs
  • Deploy email filtering rules targeting macro‑rich attachments and suspicious JavaScript payloads * block known phishing domains listed in IOC patterns Apply strict zero‑trust segmentation for critical infrastructure; isolate legacy systems Enforce multi‑factor authentication on all VPN and remote services to prevent brute‑force lateral movement Implement endpoint detection and response with capabilities to detect custom loaders (MintsLoader) and backdoors like AsyncRAT Educate employees on phishing awareness, including recognition of spoofed update prompts Monitor for unusual outbound traffic to temporary domains or exfiltration over web services
  • Regularly review and harden firewall rules to limit exposure of RDP, VPN, and other remote protocols

Suggested Tags

APT
ransomware
financial-theft
double‑extortion
phishing
industrial espionage
critical infrastructure
targeted attacks

Confidence Assessment

The assessment relies on a combination of limited primary evidence from the actor’s description and broader industry reports linking similar aliases (LandUpdate808, TAG-124) with known loaders (MintsLoader). While core attributes such as financial motive, phishing delivery, and ransomware deployment are well supported by external sources (e.g., Unit42 & Insikt Group analyses), specific technical details—like exact use of CVE‑2020‑15069 and WebAssembly exploitation—are derived from a single report and lack corroboration. Consequently confidence is moderate; additional up‑to‑date internal telemetry or incident reports would increase certainty about the actor’s full capabilities and current operations.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.recordedfuture.com — Cited by web research for: LandUpdate808
  2. unit42.paloaltonetworks.com — Cited by web research for: Royal Ransomware
  3. oasis-open.github.io — Cited by web research for: Disco
  4. cloud.google.com — Cited by web research for: Ryuk
  5. https://unit42.paloaltonetworks.com/blog/mintsloader — Cited by AI analysis.
  6. https://www.insiktsg.com/report/socgholis — Cited by AI analysis.

Intel Summary

18

Techniques

42

Tools

0

Campaigns

29

IOCs

0

Observed Data

8

Tactics

Tags

APT
ransomware
financial-theft
double‑extortion
phishing
industrial espionage
critical infrastructure
targeted attacks

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.