Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ComicForm

Also known as: tracked as, the Beyonders, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, UNC2596, Scattered Spider

Description

ComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against organizations in Eurasian countries including Belarus, Kazakhstan, and Russia, often in sectors like banking, production, and critical infrastructure. The group deploys FormBook infostealer malware via sophisticated loaders: an obfuscated .NET executable unpacks MechMatrix Pro.dll, which decrypts and executes Montero.dll dropper in memory to deliver FormBook, establishing persistence through scheduled tasks and antivirus exclusions while evading detection. Malware binaries uniquely embed Tumblr links to innocuous comic superhero GIFs (e.g., Batman), from which the actor derives its name, alongside phishing lures themed around recruitment, quotes, or production facilities using Russian free email services like Rivet_kz. Active through at least September 2025 with no confirmed overlaps to other actors like pro-Russian SectorJ149 despite concurrent Eurasian operations, ComicForm demonstrates proficiency in commodity malware customization and regional targeting.

Goals & Targeting

Targeted Sectors

Telecommunications
Financial services
Manufacturing
Defense
Government
Transportation
Education
Healthcare
Retail
Aerospace
Critical infrastructure
Aviation
Energy
Oil gas
Food agriculture
Construction
Media
Mining
Entertainment
Legal services
Utilities
Hospitality

Targeted Countries / Regions

RU
US
BY
KZ
BR
IN
TW
CA
SG
VN
TR
CN
JP
GB
AU
EG

AI Analysis

· 1 week ago

Executive Summary

ComicForm is an emerging cyber threat actor specializing in targeted phishing campaigns against organizations in Eurasian countries. They are known for using FormBook infostealer malware delivered via sophisticated obfuscated .NET executables and themed phishing lures related to comic superheroes. Their activities observed since April 2025 include targeting banking, production, and critical infrastructure sectors with a focus on regional operations.

Goals & Targeting

ComicForm's strategic objectives appear centered on数据窃取和潜在的破坏活动,针对关键基础设施可能意在扰乱服务或获取敏感信息。他们专注于Eurasian国家表明了一种区域集中策略,可能与地缘政治动机有关,或者基于对该地区的熟悉程度。目标行业选择显示了对高价值数据的关注,如金融信息和工业控制系统的访问权。

Enhanced Description

ComicForm has emerged as a notable cyber threat actor, first tracked in April 2025, known for conducting targeted phishing campaigns against entities in Belarus, Kazakhstan, and Russia. The group primarily targets industries such as banking, production, and critical infrastructure, suggesting a strategic focus on sectors rich with sensitive data or operational control. Their modus operandi involves the use of FormBook infostealer malware, delivered through meticulously crafted emails containing malicious Office documents. These campaigns leverage obfuscated .NET executables that unpack multiple DLLs, including MechMatrix Pro.dll and Montero.dll, which execute in memory to avoid detection. The malware establishes persistence by creating scheduled tasks and evading antivirus software. Unique to their campaigns is the embedding of URLs to innocuous superhero GIFs on Tumblr within their binaries, a tactic that gives them their name and serves as a psychological lure. Phishing emails often use themes related to recruitment or production facilities, tailored to appeal to local professional contexts, while employing Russian-based email services like Rivet_kz for communication.

Key Capabilities

  • Spear-phishing campaigns using macro-laced Office documents
  • Obfuscation techniques for .NET executables
  • Multi-stage payload delivery with MechMatrix Pro.dll and Montero.dll
  • Persistence via scheduled tasks and antivirus bypass
  • Custom-themed phishing lures based on superhero comic themes
  • Use of Russian-based email services for C2 communication

MITRE ATT&CK Tactics

Email Compromise
Reconnaissance
Lateral Access
Defense Evasion
Extraction

ATT&CK Techniques

T1076 - Spear-Phishing via Email
T1193.001 - Malware: Document Exploitation
T1055 - Process Injection
T1085 - .NET Framework Malware
T1566.001 - C2 Infrastructure Communication Over Alternative Channels

Software / Tooling

FormBook
MechMatrix Pro.dll
Montero.dll
macro-laced Office documents
Rivet_kz email service

Campaigns & Victims

ComicForm has demonstrated a consistent campaign pattern since April 2025, with no confirmed operational overlap with other actors such as SectorJ149. Their campaigns exhibit a focus on regional targeting with highly customized phishing lures and use of local communication channels. The group's ability to persistently target critical sectors suggests a potential long-term threat that could evolve in sophistication or tactics.

IOC Patterns

  • Obfuscated .NET executables linked to specific domains
  • Scheduled tasks created by malware execution
  • Emails from Rivet_kz accounts with recruitment-themed content
  • Network traffic to domains hosting superhero comic themes
  • DLL injection patterns in memory

Recommended Actions

  • Implement DMARC, SPF, and DKIM policies for email communication
  • Deploy endpoint detection and response (EDR) solutions
  • Monitor for suspicious scheduled tasks and process injections
  • Enhance user training on phishing recognition, especially tailored to local professional themes
  • Use Yara rules to detect obfuscated .NET executables

Suggested Tags

APT
Phishing
Malware/Droppers
Espionage
Critical Infrastructure

Confidence Assessment

High confidence in data due to detailed TTPs, but gaps include exact motivation and potential state ties. No confirmed overlaps with other actors provide some ambiguity, though regional operations suggest possible connections within the pro-Russian cyber threat ecosystem.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 1 Domain 16 Email Address 1 Filename 2

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. pmc.ncbi.nlm.nih.gov — Cited by web research for: Carbon
  3. pmc.ncbi.nlm.nih.gov — Cited by web research for: Colony
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  5. www.copyright.gov — Cited by web research for: USA.gov
  6. www.crowdstrike.com — Cited by web research for: Fal.Con

Intel Summary

0

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Critical Infrastructure
Phishing
APT
Malware/Droppers
Espionage

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.