Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ELUSIVE COMET

Also known as: Fancy Bear, Storm-0558, tracked as, the Newscaster Team, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, MiniDionis, Chinastrats, Laundry Bear, CVE-2025-59287, Salt Typhoon, RedMike, OPERATOR PANDA, UNC5807, Ghost Emperor among others, stated the document, CVE-2025-49706, CVE-2024-27564, with over 10, in FortiOS, BlueDelta, CVE-2024-6670, CVE-2024-6671, UAC-0057, used PicassoLoader, including local government offices, FamousSparrow, government, engineering, legal sectors, CVE-2022-47966, UNC2286, Newscaster, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Patchwork, Monsoon, Sarit, Dropping Elephant, APT-C-09, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION, TG-0110, Sednit, Hammertoss, Korplug, Storm-0401, APT37, SpyMax, SNOWYAMBER, CVE-2023-28121, which targeted customer emails, TeamTNT, citing overlaps in tactics, techniques, Tortoiseshell, DustSquad, BLame, MgmBot, APT-C-36, Cozy Bear, VolatileVenom

Description

ELUSIVE COMET, an actor also referenced in threat reports under multiple aliases—including Fancy Bear and APT28—has evolved into a multifaceted adversary that blends social engineering with advanced exploitation techniques. Central to the group’s modus operandi is luring users into a Zoom session, then maliciously spoofing the screen name ‘Zoom’ during a remote‑control request to obtain full system access. Once in control, the group deploys the goopdate malware which harvests credentials and cryptocurrency wallets, enabling theft of tens or hundreds of thousands of dollars worth of Bitcoin and Ethereum. In addition to these Zoom‑based assaults, ELUSIVE COMET targets a wide range of software platforms, leveraging critical vulnerabilities such as Microsoft SharePoint CVE‑2025‑49706/CVE‑2025‑49704 for ransomware delivery, a ChatGPT SSRF flaw (CVE‑2024‑27564) for high‑volume attack iterations, and flaws in Barracuda ESG, ManageEngine ServiceDesk Plus (CVE‑2022‑47966), and the WordPress Ultimate Member plugin (CVE‑2023‑3460). These exploits allow the actor to create covert administrative accounts or embed backdoors like QuiteRAT via legitimate update mechanisms such as ViPNet. The resultant payloads range from credential theft agents to destructive Warlock ransomware. The wide sector coverage—including government, defense, financial services, energy, healthcare, aerospace, manufacturing and critical infrastructure—combined with rapid exploitation of zero‑day flaws indicates an opportunistic but methodically organized campaign structure aimed at maximizing illicit gain while exploiting any available vulnerability or human error.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Non profit
Telecommunications
Education
Media
Energy
Healthcare
Aerospace
Manufacturing
Critical infrastructure
Information technology
Retail
Maritime
Think tank
Transportation
Oil gas
Hospitality
Legal services
Mining
Nuclear
Pharmaceutical
Chemical
Aviation
Entertainment
Utilities
Gaming
Construction

Targeted Countries / Regions

CN
US
UA
RU
TW
GB
IN
JP
DE
KR
IR
PK
FR
CA
KP
IL
SA
VN
BR
KZ
PL
AE
TR
AU
SG
BY
ES
RO
MX
NL
IT
IQ
SY
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

ELUSIVE COMET is a financially motivated threat actor that combines sophisticated social engineering via Zoom remote‑control spoofing with zero‑day exploitation of high‑profile software vulnerabilities to deploy malware such as the goopdate infostealer and Warlock ransomware, targeting government, financial, industrial and critical infrastructure organizations worldwide. Their attacks achieve large cryptocurrency thefts and credential compromise by exploiting both human trust and technical weaknesses.

Goals & Targeting

Strategic objectives for ELUSIVE COMET appear to center on financial gain through cryptocurrency theft and credential siphoning, supplemented by the potential to disrupt operations via ransomware. The actor’s targeting pattern reflects a blend of opportunistic exploitation—capitalizing on public CVEs and social engineering—as well as selective focus on high‑value institutions that manage sensitive digital assets or critical infrastructure, suggesting both monetary benefit and possible strategic denial-of-service motives.

Enhanced Description

Key Capabilities

  • Social engineering through fake Zoom calls and remote control spoofing using the screen name "Zoom"

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. misp-galaxy.org — Cited by web research for: Fancy Bear
  2. library.bsafes.com — Cited by web research for: Storm-0558
  3. www.malwarebytes.com — Cited by web research for: Dark
  4. cyberhoot.com — Cited by web research for: Infostealer

Intel Summary

0

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Critical Infrastructure
APT32/MalKite
Social Engineering
Cryptocurrency Theft
Email Compromise
Lateral Movement

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.