Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors MORH4x

Also known as: APT28, Pawn Storm, Fancy Bear, ArechClient2, tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, MiniDionis, Chinastrats, Sednit, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, TG-0110, Newscaster, Hammertoss, Patchwork

Description

MORH4x first surfaced in the public domain when it claimed responsibility for a mass leak of Algeria’s pharmaceutical imports, a move that appears to be both opportunistic and politically motivated. Subsequent analyses reveal a more sophisticated, financially focused threat model—an actor that routinely attacks national social‑security funds, financial institutions and defense-related sites using remote administration tools to establish deep footholds. The group’s TTP set revolves around acquiring compromised or pre‑purchased infrastructure via broker networks, then expanding reach through large‑scale phishing campaigns delivered in malicious document attachments or credential phishing. Once inside, MORH4x employs a suite of RATs (InvisibleFerret, Havex, MailSniper) and custom backdoors (IRONHALO, ELMER) to pivot laterally, exfiltrate data via both encrypted cloud endpoints and legitimate web services (Google, GitHub, Dropbox), and remain under the radar through user‑agent spoofing and code mutation. Key capabilities include exploiting known software vulnerabilities—particularly CVE‑2015‑1701 for local privilege escalation and a use‑after‑free flaw in Microsoft Word’s EPS dictionary parser—and hijacking system binaries by abusing file‑permission settings. The attacker also builds botnets over compromised third‑party infrastructure, launches DNS or web-service DoS attacks, and targets multi‑factor authentication controls, further demonstrating advanced operational security and evasion skills. Despite the public claim of a Moroccan origin, evidence suggests the actor may be a syndicate of financially motivated cybercriminals using state‑like tactics across multiple national contexts. Their operations blend espionage with extortion, targeting critical and political infrastructures worldwide while leveraging legitimate cloud platforms for persistence and exfiltration.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Media
Energy
Telecommunications
Aerospace
Manufacturing
Information technology
Education
Maritime
Think tank
Healthcare
Pharmaceutical
Chemical
Mining
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
KR
IR
RU
SA
TW
FR
CA
IL
TR
AU
KZ
PK
VN
UA
PL
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
KP
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 3 days ago

Executive Summary

MORH4x is a Moroccan‑based threat actor that blends financially driven sabotage with espionage, targeting public and critical infrastructure across governments, defense, finance, energy and other sectors in the Middle East, Europe and Asia. The group leverages pre‑compromised accounts, phishing vectors, and modern cloud services to gain initial access, maintain persistence through RATs such as InvisibleFerret and Havex, and exfiltrate data while evading detection with polymorphic code and legitimate domains.

Goals & Targeting

MORH4x appears to pursue dual objectives: generating revenue through targeted financial losses (e.g., via ransomware or data exfiltration leading to extortion) and extracting politically sensitive information across a broad spectrum of sectors—from government, defense and energy to media, academia and healthcare. The actor preferentially chooses high-value public‑sector targets that allow for lucrative ransom demands or leverage in geopolitical bargaining, while also conducting espionage against strategic industries such as aerospace, mining, and pharmaceutical supply chains.

Enhanced Description

Key Capabilities

  • Targets national social security and other public sector institutions for financial gain
  • Acquires pre‑compromised accounts or systems via broker networks to obtain initial access
  • Uses remote administration tools (InvisibleFerret, Havex RAT) for persistence
  • Exploits privilege escalation techniques (e.g., abuse of elevation controls, account manipulation)
  • Acquires infrastructure via purchase or compromise
  • Compromise existing email and cloud accounts for command & control and exfiltration
  • Leverages popular web services (Google, GitHub, Twitter, Dropbox) for stealthy C2 and phishing
  • Deploys large‑scale spam campaigns to harvest credentials
  • Builds botnets by compromising third‑party infrastructure
  • Launches denial of service attacks on DNS and web services
  • Exploits software vulnerabilities for remote code execution
  • Creates new email and cloud accounts
  • Phishing via compromised email accounts
  • Hijacks service binaries through permission misuse
  • Persistence via malicious cloud/container images
  • Spoofs browser/system attributes (User-Agent strings)
  • Targets multi‑factor authentication mechanisms
  • Acquires host service listings via port/vulnerability scans
  • Exploits CVE-2015-1701 local privilege escalation
  • Delivers malicious Microsoft Word documents exploiting EPS dictionary use‑after‑free vulnerability
  • Deploys downloader IRONHALO or backdoor ELMER
  • Uses polymorphic/mutating code to evade detection through code mutation, packing, obfuscation and encryption

MITRE ATT&CK Tactics

Initial Access
Discovery
Privilege Escalation
Persistence
Resource Development
Command and Control
Exfiltration
Credential Access
Execution
Defense Evasion
Lateral Movement
Impact

ATT&CK Techniques

T1010
T1018
T1020
T1021
T1027
T1031
T1036
T1037
T1046
T1059
T1068
T1071
T1087
T1092
T1098
T1110
T1111
T1115
T1119
T1123
T1134
T1136
T1185
T1197
T1204
T1543
T1547
T1548
T1555
T1557
T1560
T1566
T1566.001
T1580
T1583
T1584
T1586
T1595
T1609
T1612
T1613
T1619
T1650
T1651
T1659
T1671
T1499
T1526
T1531
T1538
T1554

Software / Tooling

InvisibleFerret
Havex RAT
MailSniper
IRONHALO
ELMER

Campaigns & Victims

MORH4x employs a modular approach that begins with compromised or purchased infrastructure, followed by credential phishing and the deployment of custom RATs for lateral movement. Operations are often executed through legitimate cloud services to disguise command & control traffic, while botnets harvested from third‑party servers enable scale and obfuscation. The group’s timing suggests opportunistic exploitation rather than regular, scheduled campaigns—targets appear selected based on financial value or strategic importance rather than predetermined calendars. Notable incidents include the alleged Algerian pharmaceutical data leak, attacks against Morocco’s national social security fund, and potential infiltration of various defense and energy enterprises across multiple countries. The actor demonstrates versatility by adopting both ransomware‑style extortion tactics (exploiting vulnerabilities to deliver encrypted payloads) and intelligence‑gathering campaigns that mirror nation‑state capabilities. Their operational tempo remains variable; however, the repeated use of similar infrastructure footprints (cloud services, compromised email accounts) indicates a sustainable threat model built on reusable tools and reusable access vectors. Overall, MORH4x’s campaign patterns reflect a financially driven threat group with the technological sophistication to emulate state‑level espionage while maintaining low operational footprints, allowing them to persist across national borders and industry sectors.

IOC Patterns

  • Compromised email accounts used for phishing
  • Stolen credentials for web services and cloud platforms
  • Use of legitimate domains as command & control infrastructure
  • Botnet IP collections from compromised third-party servers
  • Newly created email addresses
  • User‑Agent string spoofing
  • Suspicious DNS request spikes indicating DoS activity
  • Unusual cloud storage activity
  • Malicious Microsoft Word attachment exploiting EPS dictionary use‑after‑free vulnerability
  • Use of CVE-2015-1701 local privilege escalation

Recommended Actions

  • Implement least‑privilege access controls to limit account elevation opportunities
  • Monitor for unauthorized account creation, privilege escalation events and compromised accounts
  • Secure remote administration utilities and restrict third-party network access to critical systems
  • Enforce multi‑factor authentication on all cloud accounts and web services
  • Detect anomalous use of popular web services (Google, GitHub, Twitter, Dropbox) as command & control channels
  • Apply strict credential hygiene and monitor for account takeover activity
  • Segment networks to isolate internal resources from external interfaces
  • Maintain visibility into DNS records and flag sudden domain registrations linked to threat actors
  • Regularly patch software vulnerabilities, especially on public-facing services
  • Secure file system permissions to prevent binary hijacking or unauthorized modifications
  • Monitor anomalous User‑Agent requests and traffic spikes for early detection of DoS or spoofing attempts
  • Block unauthorized account creation in cloud environments via policy controls
  • Use container image signing and verification processes to ensure image integrity
  • Implement application whitelisting to block execution of unknown executables

Suggested Tags

financially motivated
public sector targeting
RAT usage
Privilege Escalation
Account Manipulation
Initial Access via compromised systems
Infrastructure Acquisition
Account Compromise
Web Service Abuse
Cloud Exfiltration
Botnet Formation
Phishing Operations
DoS
MFA Bypass
Service Hijack
Cloud Persistence
spear-phishing
polymorphic malware
downloader
backdoor
CVE-2015-1701
use-after-free
malicious Word attachment

Confidence Assessment

The intelligence indicates moderate confidence in MORH4x’s core capabilities—particularly the use of known RAT families, phishing tactics and cloud-based C2 channels. The attribution to a Moroccan origin is supported by self‑claimed statements but lacks independent verification; some evidence may blend distinct actor families (e.g., Butterfly, APT28). Gaps remain around precise operation timelines, exact financial impact metrics, and confirmation of all listed infrastructure acquisition methods.

ATT&CK Techniques

Exfiltration
1 technique
Lateral Movement
1 technique
Reconnaissance
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. www.sentinelone.com — Cited by web research for: Matrix
  4. https://www.resecurity.com/blog/article/cybercriminals-attacked-national-social-security-fund-of-morocco-millions-o — Cited by AI analysis.

Intel Summary

52

Techniques

45

Tools

0

Campaigns

39

IOCs

0

Observed Data

15

Tactics

Tags

Healthcare Targeting
Government Targeting
APT
nation-state
cyber espionage
North Africa
financially motivated
public sector targeting
RAT usage
Privilege Escalation
Account Manipulation
Initial Access via compromised systems
Infrastructure Acquisition
Account Compromise
Web Service Abuse
Cloud Exfiltration
Botnet Formation
Phishing Operations
DoS
MFA Bypass
Service Hijack
Cloud Persistence
spear-phishing
polymorphic malware
downloader
backdoor
CVE-2015-1701
use-after-free
malicious Word attachment

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
M
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.