Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Aggressive Inventory Zombies

Aggressive Inventory Zombies

TLP:CLEAR
Active

Also known as: AIZ, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, Turla, BOLDBADGER

Description

Aggressive Inventory Zombies (AIZ), also referred to by aliases such as APT3, Gothic Panda, and Turla, surfaced in the mid‑2010s with a focus on U.S. government agencies and has since expanded to a wide range of industry sectors including finance, retail, telecommunications, and energy. The group employs sophisticated spear‑phishing with malicious Microsoft Office attachments that exploit an EPS dictionary use‑after‑free vulnerability combined with the Windows CVE‑2015‑1701 privilege‑escalation flaw. Upon initial compromise, AIZ rapidly deploys a lightweight downloader (IRONHALO) or persistent backdoor (ELMER), and may also drop members of an extensive “Duke” tool family to maintain footholds. In addition to its government‑targeted operations, AIZ runs a sprawling retail phishing network that masquerades as legitimate cryptocurrency exchanges such as Binance and Kraken. These sites use stolen branding and inject chat services to capture credentials, while embedded Cyrillic comments serve to obfuscate code. The actor is known for reusing metadata across campaigns and executing fast break‑in attacks followed by mass exfiltration of system data. Operationally, AIZ prefers a two‑tier approach: an initial “smash‑and‑grab” phase leveraging quick privilege escalation, followed by a more subtle persistence layer that utilizes legitimate remote‑access software like TeamViewer. Throughout the lifecycle, the group demonstrates an ability to pivot tactics—shifting from noisy exfiltration to stealthy, long‑term data harvesting—making containment and detection challenging.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Retail
Telecommunications
Aerospace
Energy
Media
Education
Information technology
Healthcare
Pharmaceutical
Manufacturing
Maritime
Think tank
Chemical
Entertainment
Gaming
Hospitality
Mining
Nuclear
Legal services
Transportation
Construction
Food agriculture

Targeted Countries / Regions

US
CN
GB
IN
JP
KR
DE
RU
IR
FR
CA
SA
TW
IL
TR
AU
PK
KZ
UA
ES
PL
SG
VN
NL
BR
IT
BY
AE
IQ
MX
RO
SY
AZ
EG
LB

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 3 days ago

Executive Summary

Aggressive Inventory Zombies (AIZ) is an espionage-focused threat actor that blends large‑scale spear‑phishing campaigns with opportunistic retail crypto phishing to compromise both government and commercial targets worldwide. Using known Office and Windows vulnerabilities, AIZ delivers a custom downloader or backdoor before pivoting into long‑term exfiltration via remote tools such as TeamViewer. The operation’s breadth—spanning over three dozen countries and dozens of sectors—underscores its strategic emphasis on political influence and financial theft.

Goals & Targeting

AIZ’s primary objective is espionage coupled with financial exploitation through crypto phishing. By targeting government ministries, think tanks, and high‑profile political entities—and simultaneously building a botnet for credential theft from retail cryptocurrency users—they aim to gain strategic advantage in geopolitical affairs while funding their operations financially. Their extensive geographic reach across the U.S., Europe, Asia, and the Middle East indicates a global campaign designed to maximize both influence and revenue streams.

Enhanced Description

Key Capabilities

  • Spear‑phishing with malicious Office attachments
  • Exploitation of Office/Windows vulnerabilities for privilege escalation
  • Downloader (IRONHALO) or backdoor (ELMER) deployment
  • Large‑scale phishing against government ministries, agencies, think tanks
  • Rapid break‑in followed by mass exfiltration (smash‑and‑grab)
  • Transition to stealthy persistence and long‑term intelligence gathering
  • Deployment of a diverse malware arsenal including MiniDuke family
  • Use of legitimate remote tools (TeamViewer) for data theft
  • Retail cryptocurrency phishing network targeting Binance, Kraken etc.
  • Embedding Cyrillic text in code comments for obfuscation

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. misp-galaxy.org — Cited by web research for: cpyy
  2. www.silentpush.com — Cited by web research for: ai-tiktok.top
  3. www.silentpush.com — Cited by web research for: facebook.com
  4. chintangurjar.com — Cited by web research for: Transportation

Intel Summary

0

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Targeting
Phishing
APT
Crypto-theft

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.