Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BreachLaboratory

Also known as: other aliases, several other aliases, Turla, network, software application, APT28, Jumpy Pisces, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, root access, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, DEV-0391, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, Incransom, Qakbot, Pawn Storm, Fancy Bear, Sednit, the ALPHV Ransomware Group, ALPHV Blackcat, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505

Description

BreachLaboratory operates by targeting financial institutions, government bodies, healthcare providers and various other sectors that hold valuable personal or banking information. Initial access typically occurs through spear‑phishing campaigns that deliver malicious attachments or links, after which the actor deploys custom loaders – most notably the Latrodectus downloader and Lotus loader families – to gain persistence on compromised hosts. Once inside, the organisation’s internal database systems are surveyed for high-value data sets. The group extracts large volumes of information, including customer names, account details, SWIFT codes and other transaction identifiers, then stages this information in an organized format such as CSV or SQL dumps. These structured datasets are subsequently posted on private forums where they can be purchased by third parties. Financial gain is the primary motivation: BreachLaboratory monetises through direct sales of datasets and potentially through facilitating downstream fraud operations that exploit the stolen data. The actor demonstrates an ability to sell data for substantial amounts, having claimed to have sold approx. 950,000 records from Grupo Catalana Occidente and over 18,000 records from Bank Mandiri. While many aliases are listed in public threat‑intel sources – some of which pertain to distinct APTs such as Turla or Fancy Bear – the available evidence points specifically to BreachLaboratory’s focus on data extraction and marketplace sales rather than advanced espionage or ransomware campaigns.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Healthcare
Telecommunications
Critical infrastructure
Manufacturing
Media
Education
Energy
Aviation
Aerospace
Think tank
Non profit
Transportation
Hospitality
Maritime
Retail
Gaming
Legal services
Utilities
Nuclear

Targeted Countries / Regions

RU
CN
US
IN
IR
GB
BR
KP
TW
KR
UA
DE
CA
AU
TR
VN
FR
PK

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

BreachLaboratory is a financially driven cyber‑criminal enterprise that specialises in harvesting and selling sensitive financial data from organisations worldwide. The group infiltrates internal databases—often via phishing or database‑exploits—and then packages customer records, account numbers and SWIFT codes into CSV or SQL dumps for sale on underground forums. Its operations demonstrate a clear monetisation focus rather than a traditional espionage agenda.

Goals & Targeting

The group’s strategic objective is pure monetisation driven by the high value of raw financial datasets. By targeting global banking institutions, government ministries, and other sectors that maintain customer or transaction records, BreachLaboratory maximises its marketability on underground marketplaces. Typical victims are regional banks in Latin America, Southeast Asia, as well as large multinational banks with complex internal data stores – organisations that often lack robust database hardening and multi‑factor authentication for privileged accounts.

Enhanced Description

Key Capabilities

  • Credential harvesting via spear‑phishing
  • Custom loaders (Latrodectus, Lotus) for persistence
  • Database enumeration and extraction tools
  • Data staging into organized CSV/SQL dumps
  • Use of underground forums for data monetisation
  • Anonymised exfiltration channels (DNS tunnelling, HTTP/S tunnels)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Command and Control
Exfiltration

ATT&CK Techniques

T1566.001 - Spear‑phishing via Email
T1078.004 - Valid Accounts: Remote Services via stolen credentials
T1518.002 - Credentials from Non‑Local System Data Sources
T1041 - Exfiltration Over Command and Control Channel
T1049 - System Network Connections Discovery

Software / Tooling

Emotet (mailware distribution)
Latrodectus downloader
Lotus loader
Custom backdoor RAT
Mimikatz (credential dumping)

Campaigns & Victims

BreachLaboratory operates on a large‑scale, low‑frequency campaign model: key operations involve the compromise of sizeable financial data stores, extraction of datasets for sale, and minimal engagement with affected organisations beyond the initial breach. The actor’s activity is consistent with other financially motivated cyber‑crime syndicates that prioritize marketable information over sabotage or espionage objectives. Its notable incidents include the 2014‑style exfiltration from Spanish retailers Grupo Catalana Occidente and a 2021 incident involving Bank Mandiri in Indonesia.

IOC Patterns

  • Domain generation using short, random TLDs (e.g., demo-cloud.space)
  • Use of JavaScript-based domain tricks such as “window.dataLayer” for fileless execution
  • Fast‑flux or rotating domain patterns (TEMP.Hermit, TEMP.Zagros)

Recommended Actions

  • Institute strict database access controls and enforce least privilege; implement multi‑factor authentication for privileged accounts.
  • Deploy enterprise DLP solutions to monitor extraction of large CSV/SQL files from internal servers.
  • Enable network egress monitoring with analytics for unusual outbound traffic over HTTPS or DNS tunnels.
  • Conduct regular security awareness training focused on spear‑phishing email vectors.
  • Apply timely patches to database software and associated public‑facing services to mitigate known exploits.
  • Implement threat hunting based on the known loader signatures (Latrodectus, Lotus) and custom backdoor patterns.
  • Maintain a comprehensive audit trail of privileged access to internal data stores.

Suggested Tags

cybercrime
financial-gain
data-exfiltration
underground-marketplace
banking
government
Russia
China

Confidence Assessment

The intelligence is derived from limited public sources and a brief actor description that lists many aliases not directly linked to BreachLaboratory’s documented activities. While the reported dataset exfiltration incidents provide concrete evidence of financial motives, mapping specific MITRE techniques and tools remains partially speculative due to sparse technical details. The attribution of associated tools (e.g., Emotet) is based on common industry patterns rather than direct documentation for this actor.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 10 Domain 9 MD5 Hash 1

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. www.malwarebytes.com — Cited by web research for: network
  3. www.sentinelone.com — Cited by web research for: Singularity
  4. cert.europa.eu — Cited by web research for: CVE-2025-20281
  5. www.crowdstrike.com — Cited by web research for: Fal.Con

Intel Summary

5

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

Financial Targeting
cybercrime
financial-fraud
espionage
banking
financial-gain
data-exfiltration
underground-marketplace
government
Russia
China

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.