Also known as: UNC5356, tracked as, Octo Tempest, UNC3944
CryptoChameleon emerged in the public threat landscape as a group focused on exploiting high‑value cryptocurrency infrastructure and user accounts. Their methodology centers around highly tailored phishing kits that mimic legitimate services – most notably a recent LastPass inheritance‑request spoof – to coerce users into divulging master passwords or passkey fallback credentials. The attacker then leverages these credentials to access multiple stored logins, often spanning exchanges, wallets, and personal services. In addition to social engineering, CryptoChameleon uses SIM swapping and email compromise tactics to gain initial footholds in target accounts. They operate infrastructure from bullet‑proof hosts such as NICENIC, which provides high resilience against takedowns and allows rapid deployment of phishing host pages that are carefully engineered to evade automated scanners. A hallmark of their operations is the manual guidance of victims through malicious web portals; attackers intervene in real time to obfuscate activity, ensuring credential theft occurs before broad detection mechanisms can react. Once credentials are obtained, CryptoChameleon conducts rapid cash‑outs by moving stolen crypto assets to untraceable wallets and liquidating them across a variety of exchanges. Recent evidence – including an April 2024 phishing campaign that led to approximately $4.4 million in losses – underscores their continued relevance and evolving sophistication, demonstrating that they adapt quickly to new authentication paradigms such as passkey usage while exploiting legacy password‑manager flows.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CryptoChameleon is a financially motivated cybercriminal group that specializes in targeting cryptocurrency exchanges, wallets, and users through sophisticated phishing campaigns that exploit legitimate services such as LastPass and 1Password. They frequently employ VIP spear‑phishing, SIM swapping, and manual victim manipulation to bypass automated defenses, rapidly cashing out stolen assets via anonymous crypto wallets.
Goals & Targeting
CryptoChameleon’s primary objective is the direct financial enrichment of its operators through theft of digital assets. The group strategically targets entities with high cryptocurrency exposure – such as exchanges (Coinbase, Ledger) and individual users who rely on password managers that store wallet credentials – because successful breaches can yield large payouts in minutes. Although the actor’s publicly documented focus is the cryptocurrency domain, broader sector coverage including financial services, retail, defense, manufacturing, and government indicates a willingness to infiltrate any organization where digital currencies or valuable data are stored. Typical victims include high‑net‑worth individuals, institutional custodial wallets, and exchanges whose infrastructure is not hardened against sophisticated phishing. By exploiting authentic brand assets (e.g., LastPass) and psychological hooks such as inheritance notices, CryptoChameleon achieves high success rates while maintaining low operational risk.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CryptoChameleon consistently operates in high‑value, fast‑cash scenarios. Their campaigns typically begin with engineered spear‑phishing emails that lure users into click‑throughs on phishing sites hosted on bullet‑proof domains. Once a user reveals credentials – often through fake inheritance or emergency‑access requests – the operator manually assists to ensure credential capture and immediate exfiltration of crypto assets. The actor has demonstrated an ability to pivot across multiple cryptocurrency targets within a single operational window, as evidenced by their April 2024 LastPass campaign that yielded several million dollars in stolen coins. Operational tempo is relatively rapid; campaigns are launched shortly before the launch of new phishing kits and conclude when the stolen assets have been moved. CryptoChameleon favors manual interaction to reduce detection risk, which distinguishes it from fully automated supply‑chain or credential‑dumping threats.
IOC Patterns
Recommended Actions
Confidence Assessment
The analysis is based primarily on publicly reported phishing campaigns (notably the April 2024 LastPass inheritance attack) and confirmed usage of legitimate password‑manager services for credential theft. While these sources provide solid evidence of CryptoChameleon's social‑engineering tactics, SIM‑swapping details and broader sector targeting are inferred from general capabilities rather than direct attribution reports. Information gaps remain regarding the full range of tools beyond the phishing kit, precise infrastructure mapping, and any internal ransomware or data‑exfiltration capabilities the group may have leveraged. Sources used:
No campaigns linked yet.
No observed data linked yet.
2
Techniques
41
Tools
0
Campaigns
11
IOCs
0
Observed Data
1
Tactics