Also known as: Fancy Bear, Storm-0558, tracked as, the Newscaster Team, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, MiniDionis, Chinastrats, Laundry Bear, CVE-2025-59287, Salt Typhoon, RedMike, OPERATOR PANDA, UNC5807, Ghost Emperor among others, stated the document, CVE-2025-49706, CVE-2024-27564, with over 10, in FortiOS, BlueDelta, CVE-2024-6670, CVE-2024-6671, UAC-0057, used PicassoLoader, including local government offices, FamousSparrow, government, engineering, legal sectors, CVE-2022-47966, UNC2286, Newscaster, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Patchwork, Monsoon, Sarit, Dropping Elephant, APT-C-09, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION, TG-0110, Sednit, Hammertoss, Korplug, Storm-0401, APT37, SpyMax, SNOWYAMBER, CVE-2023-28121, which targeted customer emails, TeamTNT, citing overlaps in tactics, techniques, Tortoiseshell, DustSquad, BLame, MgmBot, APT-C-36, Cozy Bear, VolatileVenom
ELUSIVE COMET, an actor also referenced in threat reports under multiple aliases—including Fancy Bear and APT28—has evolved into a multifaceted adversary that blends social engineering with advanced exploitation techniques. Central to the group’s modus operandi is luring users into a Zoom session, then maliciously spoofing the screen name ‘Zoom’ during a remote‑control request to obtain full system access. Once in control, the group deploys the goopdate malware which harvests credentials and cryptocurrency wallets, enabling theft of tens or hundreds of thousands of dollars worth of Bitcoin and Ethereum. In addition to these Zoom‑based assaults, ELUSIVE COMET targets a wide range of software platforms, leveraging critical vulnerabilities such as Microsoft SharePoint CVE‑2025‑49706/CVE‑2025‑49704 for ransomware delivery, a ChatGPT SSRF flaw (CVE‑2024‑27564) for high‑volume attack iterations, and flaws in Barracuda ESG, ManageEngine ServiceDesk Plus (CVE‑2022‑47966), and the WordPress Ultimate Member plugin (CVE‑2023‑3460). These exploits allow the actor to create covert administrative accounts or embed backdoors like QuiteRAT via legitimate update mechanisms such as ViPNet. The resultant payloads range from credential theft agents to destructive Warlock ransomware. The wide sector coverage—including government, defense, financial services, energy, healthcare, aerospace, manufacturing and critical infrastructure—combined with rapid exploitation of zero‑day flaws indicates an opportunistic but methodically organized campaign structure aimed at maximizing illicit gain while exploiting any available vulnerability or human error.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ELUSIVE COMET is a financially motivated threat actor that combines sophisticated social engineering via Zoom remote‑control spoofing with zero‑day exploitation of high‑profile software vulnerabilities to deploy malware such as the goopdate infostealer and Warlock ransomware, targeting government, financial, industrial and critical infrastructure organizations worldwide. Their attacks achieve large cryptocurrency thefts and credential compromise by exploiting both human trust and technical weaknesses.
Goals & Targeting
Strategic objectives for ELUSIVE COMET appear to center on financial gain through cryptocurrency theft and credential siphoning, supplemented by the potential to disrupt operations via ransomware. The actor’s targeting pattern reflects a blend of opportunistic exploitation—capitalizing on public CVEs and social engineering—as well as selective focus on high‑value institutions that manage sensitive digital assets or critical infrastructure, suggesting both monetary benefit and possible strategic denial-of-service motives.
Enhanced Description
Key Capabilities
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics