Also known as: tracked as, the Beyonders, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, UNC2596, Scattered Spider
ComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against organizations in Eurasian countries including Belarus, Kazakhstan, and Russia, often in sectors like banking, production, and critical infrastructure. The group deploys FormBook infostealer malware via sophisticated loaders: an obfuscated .NET executable unpacks MechMatrix Pro.dll, which decrypts and executes Montero.dll dropper in memory to deliver FormBook, establishing persistence through scheduled tasks and antivirus exclusions while evading detection. Malware binaries uniquely embed Tumblr links to innocuous comic superhero GIFs (e.g., Batman), from which the actor derives its name, alongside phishing lures themed around recruitment, quotes, or production facilities using Russian free email services like Rivet_kz. Active through at least September 2025 with no confirmed overlaps to other actors like pro-Russian SectorJ149 despite concurrent Eurasian operations, ComicForm demonstrates proficiency in commodity malware customization and regional targeting.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ComicForm is an emerging cyber threat actor specializing in targeted phishing campaigns against organizations in Eurasian countries. They are known for using FormBook infostealer malware delivered via sophisticated obfuscated .NET executables and themed phishing lures related to comic superheroes. Their activities observed since April 2025 include targeting banking, production, and critical infrastructure sectors with a focus on regional operations.
Goals & Targeting
ComicForm's strategic objectives appear centered on数据窃取和潜在的破坏活动,针对关键基础设施可能意在扰乱服务或获取敏感信息。他们专注于Eurasian国家表明了一种区域集中策略,可能与地缘政治动机有关,或者基于对该地区的熟悉程度。目标行业选择显示了对高价值数据的关注,如金融信息和工业控制系统的访问权。
Enhanced Description
ComicForm has emerged as a notable cyber threat actor, first tracked in April 2025, known for conducting targeted phishing campaigns against entities in Belarus, Kazakhstan, and Russia. The group primarily targets industries such as banking, production, and critical infrastructure, suggesting a strategic focus on sectors rich with sensitive data or operational control. Their modus operandi involves the use of FormBook infostealer malware, delivered through meticulously crafted emails containing malicious Office documents. These campaigns leverage obfuscated .NET executables that unpack multiple DLLs, including MechMatrix Pro.dll and Montero.dll, which execute in memory to avoid detection. The malware establishes persistence by creating scheduled tasks and evading antivirus software. Unique to their campaigns is the embedding of URLs to innocuous superhero GIFs on Tumblr within their binaries, a tactic that gives them their name and serves as a psychological lure. Phishing emails often use themes related to recruitment or production facilities, tailored to appeal to local professional contexts, while employing Russian-based email services like Rivet_kz for communication.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ComicForm has demonstrated a consistent campaign pattern since April 2025, with no confirmed operational overlap with other actors such as SectorJ149. Their campaigns exhibit a focus on regional targeting with highly customized phishing lures and use of local communication channels. The group's ability to persistently target critical sectors suggests a potential long-term threat that could evolve in sophistication or tactics.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in data due to detailed TTPs, but gaps include exact motivation and potential state ties. No confirmed overlaps with other actors provide some ambiguity, though regional operations suggest possible connections within the pro-Russian cyber threat ecosystem.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics