Also known as: AIZ, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, Turla, BOLDBADGER
Aggressive Inventory Zombies (AIZ), also referred to by aliases such as APT3, Gothic Panda, and Turla, surfaced in the mid‑2010s with a focus on U.S. government agencies and has since expanded to a wide range of industry sectors including finance, retail, telecommunications, and energy. The group employs sophisticated spear‑phishing with malicious Microsoft Office attachments that exploit an EPS dictionary use‑after‑free vulnerability combined with the Windows CVE‑2015‑1701 privilege‑escalation flaw. Upon initial compromise, AIZ rapidly deploys a lightweight downloader (IRONHALO) or persistent backdoor (ELMER), and may also drop members of an extensive “Duke” tool family to maintain footholds. In addition to its government‑targeted operations, AIZ runs a sprawling retail phishing network that masquerades as legitimate cryptocurrency exchanges such as Binance and Kraken. These sites use stolen branding and inject chat services to capture credentials, while embedded Cyrillic comments serve to obfuscate code. The actor is known for reusing metadata across campaigns and executing fast break‑in attacks followed by mass exfiltration of system data. Operationally, AIZ prefers a two‑tier approach: an initial “smash‑and‑grab” phase leveraging quick privilege escalation, followed by a more subtle persistence layer that utilizes legitimate remote‑access software like TeamViewer. Throughout the lifecycle, the group demonstrates an ability to pivot tactics—shifting from noisy exfiltration to stealthy, long‑term data harvesting—making containment and detection challenging.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Aggressive Inventory Zombies (AIZ) is an espionage-focused threat actor that blends large‑scale spear‑phishing campaigns with opportunistic retail crypto phishing to compromise both government and commercial targets worldwide. Using known Office and Windows vulnerabilities, AIZ delivers a custom downloader or backdoor before pivoting into long‑term exfiltration via remote tools such as TeamViewer. The operation’s breadth—spanning over three dozen countries and dozens of sectors—underscores its strategic emphasis on political influence and financial theft.
Goals & Targeting
AIZ’s primary objective is espionage coupled with financial exploitation through crypto phishing. By targeting government ministries, think tanks, and high‑profile political entities—and simultaneously building a botnet for credential theft from retail cryptocurrency users—they aim to gain strategic advantage in geopolitical affairs while funding their operations financially. Their extensive geographic reach across the U.S., Europe, Asia, and the Middle East indicates a global campaign designed to maximize both influence and revenue streams.
Enhanced Description
Key Capabilities
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
39
IOCs
0
Observed Data
0
Tactics