Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors EC2 Grouper

Also known as: tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, SkyCloak, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

EC2 Grouper is a highly adaptable threat actor that leverages Amazon Web Services as a launchpad for automated attacks, specifically by creating custom security groups to facilitate remote ingress. The group obtains compromised cloud access keys from code repositories, then uses PowerShell scripts and AWS SDK calls to establish persistence and lateral movement within target environments. Beyond its cloud‑centric tactics, EC2 Grouper has demonstrated traditional malware development, deploying a suite of remote access trojans—Remcos RAT, Sunburst (the SolarWinds supply‑chain tool), Brute Ratel C4, Havex RAT—as well as infostealer payloads such as FormBook. The actor’s operational playbook includes exploitation of publicly disclosed CVEs (CVE‑2017‑0199, CVE‑2024‑36401) and zero‑day vulnerabilities like CVE‑2013‑3893 to gain initial access. Phishing campaigns are often crafted in JavaScript to lure victims into executing malicious attachments or visiting compromised websites. Supply‑chain attacks target NPM packages and other third‑party libraries, expanding the attack surface for credential theft and data exfiltration. EC2 Grouper’s activities align with broader APT operations—sharing many aliases such as DeputyDog, Fancy Bear and Dark—yet maintain a distinct focus on leveraging cloud infrastructure. Their recent use of Amazon Web Services indicates an evolving methodology designed to lower attribution risk while preserving high‑impact reach.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Non profit
Energy
Education
Hospitality
Critical infrastructure
Media
Aerospace
Mining
Pharmaceutical
Maritime
Gaming
Nuclear
Information technology
Retail
Aviation
Manufacturing
Think tank
Legal services
Transportation
Utilities
Chemical
Entertainment

Targeted Countries / Regions

CN
US
IR
GB
IN
JP
KR
TW
UA
DE
CA
RU
PL
FR
SA
TR
AU
AE
SG
IL
BR
IT
RO
KZ
PK
KP
ES
VN
MX
NL
IQ
BY
SY
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 11 hours ago

Executive Summary

EC2 Grouper is a multi‑faceted threat actor that combines cloud‑infrastructure manipulation, zero‑day exploits and supply‑chain attacks to compromise high‑value targets across a wide range of sectors. Using AWS APIs for automated security‑group creation, the group harvests credentials from publicly exposed cloud keys and deploys remote access trojans such as Remcos, Sunburst and Havex RAT to exfiltrate data and elevate privileges. Recent activity shows the exploitation of the CVE‑2013‑3893 client vulnerability and ongoing phishing campaigns aimed at Japanese organizations.

Goals & Targeting

The actor’s primary objective appears to be financial gain through data exfiltration and illicit monetization, supplemented by strategic espionage via supply‑chain compromises. By targeting a broad spectrum—government, defense, telecommunications, healthcare, critical infrastructure, and education—they seek to infiltrate varied environments that house valuable credentials or sensitive data. The repeated focus on Japanese organizations underscores a geopolitical dimension, potentially aimed at gathering competitive intelligence or influencing regional affairs. Strategically, EC2 Grouper blends cloud‑native execution with traditional zero‑day exploits to avoid detection and simplify lateral movement across heterogeneous infrastructures. Credential harvesting from exposed code further indicates a low‑effort but high-reward approach, enabling the exploitation of legitimate AWS services before moving to client‑side attacks. Overall, their targeting profile suggests a hybrid motive: profiteering while opportunistically collecting intelligence that can be later leveraged for political or economic influence.

Enhanced Description

Key Capabilities

  • Phishing campaigns
  • Exploitation of publicly disclosed CVEs (CVE-2017-0199, CVE-2024-36401, CVE-2013-3893)
  • Remote access trojans – Remcos RAT, Sunburst (SolarWinds), Brute Ratel C4, Havex RAT
  • Infostealer payloads such as FormBook
  • Supply‑chain attacks on npm packages and third‑party libraries
  • Zero‑day vulnerability exploitation (CVE‑2013-3893)
  • Targeted attacks against Japanese organizations
  • Use of AWS Cloud tools for automated attacks via CreateSecurityGroup API
  • Credential acquisition through compromised cloud keys in public code repositories

MITRE ATT&CK Tactics

Initial Access
Execution

ATT&CK Techniques

T1203

Software / Tooling

Remcos RAT
Sunburst (SolarWinds)
Brute Ratel C4
Havex RAT
FormBook
PowerShell
Node.js
AWS CLI

Campaigns & Victims

EC2 Grouper’s campaign pattern shows a combination of long‑term infrastructure deployment—such as automated security group creation in the cloud—and episodic zero‑day exploitation, exemplified by the 2013 CVE‑2013‑3893 operation against Japanese targets and more recent CVE‑2024‑36401 exploits. The actor maintains an operational tempo that allows periodic bursts of activity while keeping a low public profile. Victims span critical infrastructure, defense, finance, and educational sectors across Asia, Europe, the Americas, and Middle East, demonstrating geographic flexibility. Their preferred tactics include phishing for initial credential collection, followed by installation of remote access trojans or supply‑chain implants, which provide persistent footholds and extensive lateral movement. Notable operations such as Operation DeputyDog (CVE‑2013‑3893) and the reported supply‑chain compromise of an npm package highlight the group’s capacity to blend classic APT workflows with modern cloud‑native methods. In addition to data exfiltration, the actor appears equipped for sabotage or espionage via its supply‑chain footholds, indicating a multi‑layered threat model that spans both financial and strategic objectives.

IOC Patterns

  • Domain
  • URL
  • File
  • CVE identifier: CVE-2013-3893
  • Zero‑day exploit

Recommended Actions

  • Secure cloud credentials by rotating keys regularly and storing them in a secrets management system separate from public code repositories. Configure AWS GuardDuty or similar monitoring to alert on anomalous CreateSecurityGroup API calls, especially those not accompanied by corresponding AuthorizeSecurityGroupIngress actions. Ensure Windows endpoints are patched against CVE-2013-3893, CVE‑2017‑0199, CVE‑2024‑36401 and other known vulnerabilities; use automated patching tools where possible. Deploy email filtering solutions with attachment sandboxing to block malicious Office documents and JavaScript phishing payloads. Implement strict outbound egress controls and DLP to detect data exfiltration associated with Remcos RAT, Sunburst, Havex, or FormBook activity. Use application whitelisting and behavior analytics to detect rogue RATs and infostealer binaries on endpoints. Apply supply‑chain monitoring—verify npm package checksums, use package signing or a private registry, and conduct code reviews to mitigate compromised dependencies. Block or monitor known malicious domains such as demo-cloud.space, attack.mitre.org, cisa.gov, Temp.* domains listed in IOC sets.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. misp-galaxy.org — Cited by web research for: cpyy
  2. www.fortinet.com — Cited by web research for: Global
  3. www.varutra.com — Cited by web research for: WhatsApp
  4. threats.wiz.io — Cited by web research for: Backdoors
  5. www.demo-cloud.space — Cited by web research for: www.demo-cloud.space

Intel Summary

1

Techniques

47

Tools

0

Campaigns

43

IOCs

0

Observed Data

1

Tactics

Tags

Critical Infrastructure
Backdoor / C2
APT
cloud-based
AWS
credential-theft
enterprise-targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.