Also known as: APT28, tracked as, Clickfix, SOC Prime, UAC-0001, Fancy Bear APT, SkyCloak, fakeCAPTCHA
Mocha Manakin represents a highly adaptable threat group with roots in the APT28 family. Leveraging social engineering such as paste‑and‑run lures and spearphishing links, the operator coerces victims to execute obfuscated PowerShell scripts that download a NodeJS‑based RAT (NodeInitRAT). After execution, the backdoor establishes persistence by writing a Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run – commonly named "ChromeUpdater" – and employs a variety of native Windows utilities for reconnaissance. The actor’s toolkit includes a custom NodeJS environment that spawns cmd.exe processes to deploy further binaries, a set of infostealer payloads (LummaC2, HijackLoader, Vidar), and the use of the Cloudflare front‑end to host malicious components, often under trycloudflare.com domains. Communication is obfuscated with XOR encoding and GZIP compression, making detection challenging. Mocha Manakin also demonstrates breadth in lateral movement tactics, using commands such as nltest, net.exe, and setspn.exe for domain enumeration and SPP discovery. Notably, the group has exploited a zero‑day vulnerability (CVE-2022-30190) to deliver CredoMap malware through lure attachments; they have also been linked to Interlock ransomware activities, though direct deployment of ransomware remains unconfirmed. Their modus operandi suggests opportunistic operations aimed at financial compromise and data exfiltration across multiple high‑value sector targets.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Mocha Manakin, an APT28 activity cluster, uses a sophisticated paste‑and‑run social engineering technique to launch obfuscated PowerShell commands that download and deploy a NodeJS backdoor (NodeInitRAT). The actor achieves persistence via registry Run keys (e.g., ChromeUpdater), performs extensive network and host reconnaissance, and channels command & control traffic through Cloudflare tunnels. While their primary motive is financial gain, they target a wide spectrum of sectors across the globe.
Goals & Targeting
Mocha Manakin’s strategic objectives revolve around maximizing illicit revenue streams by compromising a diverse set of industries—financial services, healthcare, critical infrastructure, defense, and more—across geopolitically significant regions. By employing low‑cost social engineering vectors (paste‑and‑run) combined with sophisticated persistence mechanisms, the actor maintains long‑term footholds while collecting credential and network data for potential sell‑off or further exploitation. The inclusion of the Interlock ransomware family in their toolset indicates a readiness to capitalize on exploitative opportunities should the opportunity arise.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The actor’s campaigns exhibit a blend of opportunistic phishing, social engineering copy‑paste lures, and zero‑day exploitation, with evidence dating to at least 2022. Their operations are largely low‑profile, leveraging generic services (Cloudflare) for C&C, yet they persistently target high-value sectors across dozens of countries. Past incidents include a targeted phishing wave against Ukrainian state bodies in 2023 and the deployment of CredoMap via a CVE-2022-30190 exploit in mid‑2022. While direct ransomware delivery (Interlock) has not been confirmed, the threat landscape suggests readiness to pivot toward more aggressive extortion if viable targets present themselves.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data set provides a robust depiction of Mocha Manakin’s tactics, techniques, and procedures with high confidence regarding the use of paste‑and‑run social engineering, PowerShell-based execution, NodeJS backdoor persistence, and Cloudflare-based command & control. Attribution uncertainty remains due to overlapping aliases (APT28, Fancy Bear) and limited disclosure on underlying infrastructure beyond the generic Cloudflare front‑end. Knowledge gaps include precise deployment dates for certain weaponized attachments, confirmed ransomware delivery instances, and evidence of lateral movement mechanisms within large organizations.“,
No campaigns linked yet.
No observed data linked yet.
14
Techniques
48
Tools
0
Campaigns
37
IOCs
0
Observed Data
6
Tactics