Also known as: tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, SkyCloak, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
EC2 Grouper is a highly adaptable threat actor that leverages Amazon Web Services as a launchpad for automated attacks, specifically by creating custom security groups to facilitate remote ingress. The group obtains compromised cloud access keys from code repositories, then uses PowerShell scripts and AWS SDK calls to establish persistence and lateral movement within target environments. Beyond its cloud‑centric tactics, EC2 Grouper has demonstrated traditional malware development, deploying a suite of remote access trojans—Remcos RAT, Sunburst (the SolarWinds supply‑chain tool), Brute Ratel C4, Havex RAT—as well as infostealer payloads such as FormBook. The actor’s operational playbook includes exploitation of publicly disclosed CVEs (CVE‑2017‑0199, CVE‑2024‑36401) and zero‑day vulnerabilities like CVE‑2013‑3893 to gain initial access. Phishing campaigns are often crafted in JavaScript to lure victims into executing malicious attachments or visiting compromised websites. Supply‑chain attacks target NPM packages and other third‑party libraries, expanding the attack surface for credential theft and data exfiltration. EC2 Grouper’s activities align with broader APT operations—sharing many aliases such as DeputyDog, Fancy Bear and Dark—yet maintain a distinct focus on leveraging cloud infrastructure. Their recent use of Amazon Web Services indicates an evolving methodology designed to lower attribution risk while preserving high‑impact reach.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
EC2 Grouper is a multi‑faceted threat actor that combines cloud‑infrastructure manipulation, zero‑day exploits and supply‑chain attacks to compromise high‑value targets across a wide range of sectors. Using AWS APIs for automated security‑group creation, the group harvests credentials from publicly exposed cloud keys and deploys remote access trojans such as Remcos, Sunburst and Havex RAT to exfiltrate data and elevate privileges. Recent activity shows the exploitation of the CVE‑2013‑3893 client vulnerability and ongoing phishing campaigns aimed at Japanese organizations.
Goals & Targeting
The actor’s primary objective appears to be financial gain through data exfiltration and illicit monetization, supplemented by strategic espionage via supply‑chain compromises. By targeting a broad spectrum—government, defense, telecommunications, healthcare, critical infrastructure, and education—they seek to infiltrate varied environments that house valuable credentials or sensitive data. The repeated focus on Japanese organizations underscores a geopolitical dimension, potentially aimed at gathering competitive intelligence or influencing regional affairs. Strategically, EC2 Grouper blends cloud‑native execution with traditional zero‑day exploits to avoid detection and simplify lateral movement across heterogeneous infrastructures. Credential harvesting from exposed code further indicates a low‑effort but high-reward approach, enabling the exploitation of legitimate AWS services before moving to client‑side attacks. Overall, their targeting profile suggests a hybrid motive: profiteering while opportunistically collecting intelligence that can be later leveraged for political or economic influence.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
EC2 Grouper’s campaign pattern shows a combination of long‑term infrastructure deployment—such as automated security group creation in the cloud—and episodic zero‑day exploitation, exemplified by the 2013 CVE‑2013‑3893 operation against Japanese targets and more recent CVE‑2024‑36401 exploits. The actor maintains an operational tempo that allows periodic bursts of activity while keeping a low public profile. Victims span critical infrastructure, defense, finance, and educational sectors across Asia, Europe, the Americas, and Middle East, demonstrating geographic flexibility. Their preferred tactics include phishing for initial credential collection, followed by installation of remote access trojans or supply‑chain implants, which provide persistent footholds and extensive lateral movement. Notable operations such as Operation DeputyDog (CVE‑2013‑3893) and the reported supply‑chain compromise of an npm package highlight the group’s capacity to blend classic APT workflows with modern cloud‑native methods. In addition to data exfiltration, the actor appears equipped for sabotage or espionage via its supply‑chain footholds, indicating a multi‑layered threat model that spans both financial and strategic objectives.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
1
Techniques
47
Tools
0
Campaigns
43
IOCs
0
Observed Data
1
Tactics