Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNK_RemoteRogue

Also known as: APT28, Fancy Bear, tracked as, Midnight Blizzard has, conference Wi-Fi portals worldwide, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, BokBot, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin

Description

UNK_RemoteRogue employs an evolutionarily layered attack chain that begins with spear‑phishing emails bearing malicious attachments or links. By spoofing legitimate company domains, the actor bypasses email security controls and delivers PowerShell scripts or WMI commands to establish persistence via scheduled tasks or autostart mechanisms. Once inside, it exploits well‑known CVEs in webmail platforms—including XSS weaknesses in MDaemon, Horde, Zimbra, Roundcube, and WebDAV flaws (CVE‑2012‑0158, CVE‑2025‑33053)—to inject JavaScript payloads that harvest credentials, emails and contact lists. After initial access, the attacker deploys a suite of RATs such as DarkGate, BrockenDoor, Remcos, Havoc, HanifNet, HXLibrary, and NeoExpressRAT. These backdoors provide remote command execution, credential dumping with Mimikatz, and facilitate lateral movement using legitimate tunneling utilities like plink and Ngrok. Persistence is further hardened via scheduled tasks and autostart entries (e.g., through T1047 WMI or T1547 boot‑logon scripts). The actor also routinely utilizes the SDelete utility to cleanse backups, enabling ransomware deployments such as Babuk in campaigns demanding extortion. UNK_RemoteRogue’s operational tempo shows a pattern of multi‑month campaigns with periodic updates to exploitation tools. Their global attack footprint spans high‑value sectors—including financial services, defense, telecommunications, energy, healthcare and critical infrastructure—in dozens of countries across Eurasia, the Middle East and North America.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Media
Telecommunications
Energy
Manufacturing
Transportation
Education
Critical infrastructure
Utilities
Construction
Healthcare
Retail
Aerospace
Hospitality
Information technology
Nuclear
Non profit
Aviation
Oil gas
Think tank

Targeted Countries / Regions

RU
US
KP
IR
TW
KR
IL
AE
BR
TR
UA
SA
CA
JP
VN
IN
AU
CN

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 days ago

Executive Summary

UNK_RemoteRogue is a state‑level threat actor believed to originate from Russia that blends traditional phishing with sophisticated webmail exploitation and the use of legitimate tunneling tools for lateral movement. The group routinely leverages publicly available WebDAV, Office, and XSS vulnerabilities in front‑end mail clients to deploy JavaScript backdoors, then pivots through RDP, SSH or VPN portals while installing RATs such as DarkGate, BrockenDoor or Remcos. Recent campaigns have additionally incorporated ransomware delivery (Babuk) and click‑based phishing via ClickFix, targeting a broad range of sectors and countries worldwide.

Goals & Targeting

The actor’s strategic objectives appear to be a mix of espionage, sabotage and financial gain. By compromising privileged accounts through stolen VPN credentials or credential dumping, RemoteRogue seeks direct access to classified or proprietary data within targeted organizations. The deployment of ransomware suggests monetization as an additional motive once the actor perceives an opportunity for high‑value ransom payouts. Operationally, the group selects victims that provide either actionable intelligence (e.g., defense contractors, telecom operators) or sizable financial influence, reflecting a dual use of espionage and extortion to advance national strategic interests.

Enhanced Description

Key Capabilities

  • phishing emails with malicious attachments
  • impersonation of legitimate companies using fake domains
  • use of Back‑door RATs such as DarkGate, BrockenDoor and Remcos
  • living‑off‑the‑Land techniques via PowerShell and WMI
  • persistence through scheduled tasks on Windows
  • privilege escalation using compromised employee accounts
  • remote access over RDP, SSH or VPN
  • deletion of backups with the SDelete utility
  • deployment of Babuk ransomware in selected campaigns
  • exploitation of XSS vulnerabilities in webmail clients to deliver malicious JavaScript payloads
  • spear‑phishing via malicious links or Remote Management tool installers
  • exploitation of Office and WebDAV CVE vulnerabilities (CVE‑2012‑0158, CVE‑2025‑33053)
  • use of stolen credentials to access SSL VPN systems
  • deployment of web shells on publicly accessible servers
  • installation of additional backdoors such as Havoc, HanifNet, HXLibrary and NeoExpressRAT
  • utilization of legitimate tunneling tools (plink, Ngrok) for lateral movement
  • execution of custom loaders and injectors that reflectively load malware into memory
  • credential dumping with Mimikatz
  • click‑based phishing delivery via ClickFix

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1566.001
T1566.002
T1059.003
T1047
T1053.005
T1070.004
T1218
T1547
T1098
T1115
T1071
T1659
T1560
T1020
T1037

Software / Tooling

DarkGate
BrockenDoor
Remcos
Babuk Ransomware
SpyPress.HORDE
SpyPress.MDAEMON
SpyPress.ROUNDCUBE
SpyPress.ZIMBRA
Elise
Havoc
HanifNet
HXLibrary
NeoExpressRAT
plink
Ngrok
MeshCentral Agent
SystemBC
Mimikatz
Syncro RMM
PDQ RMM
ClickFix

Campaigns & Victims

UNK_RemoteRogue typically launches multi‑month, phased campaigns that begin with globally distributed spear‑phishing messages and pivot through exploitation of webmail XSS or CVE vulnerabilities. The actor has demonstrated a preference for targeting mid‑level to senior‑tier employees in industries such as defense, telecom, finance and critical infrastructure. In addition to exfiltration and espionage, the group occasionally leverages ransomware (Babuk) when backups are corrupted by SDelete, creating both financial leverage and operational disruption. The operational tempo appears cyclical with periods of quiet intermission between waves; however, recent observations confirm renewed activity in 2024–25, including documented ClickFix usage against a broad developer community.

IOC Patterns

  • malicious email attachments used in spear‑phishing
  • fake domains mimicking legitimate company names
  • XSS vulnerability exploitation in webmail clients (e.g., MDaemon, Horde, Zimbra)
  • PowerShell usage for living‑off‑the‑Land operations
  • WMI-based lateral movement or persistence
  • scheduling of tasks for persistence
  • SDelete utility deployment to wipe backups
  • Backdoor RATs such as DarkGate, BrockenDoor and Remcos
  • Web shell installation on publicly accessible servers
  • Custom loader injections into memory (reflective DLL loading)
  • Credential dumping via Mimikatz
  • Exploitation of Office CVE‑2012‑0158 and WebDAV CVE‑2025‑33053
  • Use of legitimate tunneling tools like plink, Ngrok for covert exfiltration

Recommended Actions

  • Block malicious attachments at the email gateway
  • Monitor PowerShell execution for unauthorized activity
  • Detect and block suspicious WMI usage
  • Implement scheduled task monitoring and alerting for anomalous entries
  • Patch XSS CVE‑2024‑11182 in MDaemon and other webmail services immediately
  • Verify domain authenticity to prevent spoofed sender addresses
  • Deploy EDR solutions that detect backdoor RATs such as DarkGate, BrockenDoor and Remcos
  • Maintain off‑site backups with integrity validation and protect against deletion utilities
  • Conduct phishing awareness training and spear‑phishing simulations for users
  • Apply patches for Office CVE‑2012‑0158 and WebDAV CVE‑2025‑33053 immediately
  • Patch systems against Biotime CVEs (CVE‑2023‑38950/51/52)
  • Implement multi‑factor authentication on VPN and corporate accounts
  • Monitor RMM software usage and audit installation logs for unauthorized instances to detect malicious remote tools
  • Detect and block web shells by monitoring unfamiliar scripts or binaries in public server directories
  • Deploy endpoint detection that flags custom loaders, injectors and memory‑resident backdoors

Suggested Tags

phishing
email attachment delivery
spoofing
backdoor RATs
malware
PowerShell
WMI
scheduled tasks
SDelete
backup deletion
XSS
webmail exploitation
data exfiltration
remote protocols (RDP/SSH/VPN)
ransomware
Babuk
DarkGate
BrockenDoor
Billbug
Lemon Sandstorm
Stealth Falcon
MuddyWater
spear-phishing
webshell
credential dumping
RMM tools
custom loader
exploitation

Confidence Assessment

The assessment is based on multiple independent publications, publicly disclosed threat reports and known tool footprints. High confidence exists regarding the use of phishing, webmail exploitation through XSS/CVE avenues, deployment of RATs (DarkGate, BrockenDoor, Remcos), and ClickFix‑based delivery. However, attribution gaps remain in precise campaign dates, full attack timelines, and the extent of ransomware usage outside a few documented incidents. Continuous monitoring is needed to validate ongoing activity and assess shifts in tactics.

ATT&CK Techniques

Exfiltration
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 5 Email Address 1 URL 8 Filename 3 Domain 3

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. attack.mitre.org — Cited by web research for: services
  3. www.proofpoint.com — Cited by web research for: Trixauvex
  4. www.proofpoint.com — Cited by web research for: QuasarRAT
  5. https://malpedia.caad.fkie.fraunhofer.de/actor/apt33 — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat — Cited by AI analysis.
  7. https://www.facebook.com/slashdot/posts/a-russia-linked-group-tracked-as-midnight-blizzard-has-comprom — Cited by AI analysis.
  8. https://thehackernews.com/2025/04/state-sponsored-hackers-weaponize.html — Cited by AI analysis.
  9. https://attack.mitre.org/ — Cited by AI analysis.
  10. https://hackread.com/north-korea-iran-russia-hackers-clickfix-attacks/ — Cited by AI analysis.

Intel Summary

46

Techniques

61

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Critical Infrastructure
Phishing
Russian Actor
Finance Sector
Government Targeting
phishing
email attachment delivery
spoofing
backdoor RATs
malware
PowerShell
WMI
scheduled tasks
SDelete
backup deletion
XSS
webmail exploitation
data exfiltration
remote protocols (RDP/SSH/VPN)
ransomware
Babuk
DarkGate
BrockenDoor
Billbug
Lemon Sandstorm
Stealth Falcon
MuddyWater
spear-phishing
webshell
credential dumping
RMM tools
custom loader
exploitation

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.