Also known as: APT28, Earth Preta, Pawn Storm, Fancy Bear, RedDelta, Cozy Bear, Bronze President, HoneyMyte, Red Lich, Krypton, APT36, Operation C-Major, PROJECTM, Mythic Leopard, DEV-0569, Lotus Blossom, ArechClient2, tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, MiniDionis, Chinastrats, cyber-espionage tools, LAUNDRY BEAR, Ukraine, GOFFEE, custom UPX packers, Internet scanning, cryptomining malware like XMRig, EquationCorp, Kimusky, TA427, Blue Callisto, Spring Dragon, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Billbug, Patchwork, Monsoon, Sarit, Dropping Elephant, APT-C-09, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini, COLDRIVER, SEABORGIUM, TA446, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Newscaster, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION, Sednit, Midnight Blizzard, TG-0110, Hammertoss, Silk Typhoon, Mexals, watering hole attacks, Ethereal Panda, Jupiter, Storm-0401, Aqua Blizzard, Armageddon, Shuckworm, UAC-0010, Silent Chollima, Stonefly, Nobelium, APT15, BackdoorDiplomacy, ke3chang, Storm-0950, TA505, Evil Corp, Mustang Panda, Roasted 0ktapus, Scattered Spider, BASIN, HOODOO, Winnti, Bronze Highland, Daggerfly, Hong Kong, other countries locat, APT29, Secre The Hacker News, military personnel, defense contractors, educational entities, APT43, Linux backdoor called KEYPLUG, COLD RELIC, Evasive Panda, OperationTroy, Guardian of Peace, GOP, WHOis Team, Andariel, Subgroup: Andariel, Onyx Sleet, PLUTONIUM, DarkHalo, StellarParticle, NOBELIUM, Solar Phoenix
CashRewindo has been tracked by security analysts as an advanced threat actor that leverages aged domains in global malvertising networks to funnel users into investment scams. The organization’s approach includes alternating benign ad content with malicious call‑to‑action advertisements, a tactic designed to outmaneuver time‑based creative verification systems that examine ad load times. The group also conducts A/B testing across campaigns, ensuring that the transition between decoy and malicious content is seamless for unsuspecting users. Technically, CashRewindo injects malware into widely used JavaScript libraries, effectively piggybacking on trusted assets to deliver its payloads without requiring a direct download from the user. This method allows the actor to bypass standard security controls that focus on file downloads or executable binaries and to maintain an extended presence on compromised hosts. Geographically, malicious campaigns are localized in language and imagery, supporting operations across Europe, Asia, Africa, and the Americas. The actor’s breadth of target industries—from government and defense to finance, energy, healthcare, critical infrastructure, aerospace, maritime, academia, and more—reflects a diversified threat model that blends financial fraud with covert espionage objectives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CashRewindo is a sophisticated threat actor that exploits aged domains in global malvertising campaigns, steering victims toward investment‑scam sites while intermittently delivering malicious JavaScript payloads embedded within legitimate libraries. The group employs A/B testing against ad‑verification systems, switching between innocuous and call‑to‑action ads to evade detection. Their operations span multiple continents and target sectors ranging from government and defense to finance and healthcare.
Goals & Targeting
CashRewindo seeks to extract financial gains through investment‑scam funnels while simultaneously collecting intelligence from a wide spectrum of sectors. By targeting high‑profile industries such as defense, energy, transportation, and medical research across dozens of countries—including China, the United States, Ukraine, India, Russia, Iran, Japan, and many others—the actor maximizes the value of compromised data and facilitates long‑term influence operations. Typical victims include mid‑ to large‑scale organizations that rely heavily on third‑party web services and are more likely to engage with ad networks, making them attractive prey for malvertising delivery.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CashRewindo’s campaigns are initiated by placing aged domains across ad networks, then using a staged approach that first presents harmless ads to build trust before switching to malicious calls‑to‑action. The actor applies A/B testing methodology, constantly iterating on creative elements and exploiting the time window of ad verification processes. Operational tempo appears moderately high; new variants are released regularly across multiple regions, focusing on high‑value target sectors while maintaining low visibility by leveraging legitimate JavaScript libraries as a delivery vector.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based primarily on a 2022 Confiant article and the group description, giving moderate confidence in the actor’s use of malvertising, aged domains, and JavaScript injection. Recent activity data, precise tool lists, and advanced persistence mechanisms are not well documented, creating gaps regarding exact capabilities and operational cadence.
No campaigns linked yet.
No observed data linked yet.
4
Techniques
47
Tools
0
Campaigns
32
IOCs
0
Observed Data
1
Tactics