Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CashRewindo

Also known as: APT28, Earth Preta, Pawn Storm, Fancy Bear, RedDelta, Cozy Bear, Bronze President, HoneyMyte, Red Lich, Krypton, APT36, Operation C-Major, PROJECTM, Mythic Leopard, DEV-0569, Lotus Blossom, ArechClient2, tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, MiniDionis, Chinastrats, cyber-espionage tools, LAUNDRY BEAR, Ukraine, GOFFEE, custom UPX packers, Internet scanning, cryptomining malware like XMRig, EquationCorp, Kimusky, TA427, Blue Callisto, Spring Dragon, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Billbug, Patchwork, Monsoon, Sarit, Dropping Elephant, APT-C-09, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini, COLDRIVER, SEABORGIUM, TA446, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Newscaster, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION, Sednit, Midnight Blizzard, TG-0110, Hammertoss, Silk Typhoon, Mexals, watering hole attacks, Ethereal Panda, Jupiter, Storm-0401, Aqua Blizzard, Armageddon, Shuckworm, UAC-0010, Silent Chollima, Stonefly, Nobelium, APT15, BackdoorDiplomacy, ke3chang, Storm-0950, TA505, Evil Corp, Mustang Panda, Roasted 0ktapus, Scattered Spider, BASIN, HOODOO, Winnti, Bronze Highland, Daggerfly, Hong Kong, other countries locat, APT29, Secre The Hacker News, military personnel, defense contractors, educational entities, APT43, Linux backdoor called KEYPLUG, COLD RELIC, Evasive Panda, OperationTroy, Guardian of Peace, GOP, WHOis Team, Andariel, Subgroup: Andariel, Onyx Sleet, PLUTONIUM, DarkHalo, StellarParticle, NOBELIUM, Solar Phoenix

Description

CashRewindo has been tracked by security analysts as an advanced threat actor that leverages aged domains in global malvertising networks to funnel users into investment scams. The organization’s approach includes alternating benign ad content with malicious call‑to‑action advertisements, a tactic designed to outmaneuver time‑based creative verification systems that examine ad load times. The group also conducts A/B testing across campaigns, ensuring that the transition between decoy and malicious content is seamless for unsuspecting users. Technically, CashRewindo injects malware into widely used JavaScript libraries, effectively piggybacking on trusted assets to deliver its payloads without requiring a direct download from the user. This method allows the actor to bypass standard security controls that focus on file downloads or executable binaries and to maintain an extended presence on compromised hosts. Geographically, malicious campaigns are localized in language and imagery, supporting operations across Europe, Asia, Africa, and the Americas. The actor’s breadth of target industries—from government and defense to finance, energy, healthcare, critical infrastructure, aerospace, maritime, academia, and more—reflects a diversified threat model that blends financial fraud with covert espionage objectives.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Non profit
Education
Energy
Media
Healthcare
Maritime
Critical infrastructure
Aerospace
Manufacturing
Transportation
Information technology
Chemical
Think tank
Nuclear
Pharmaceutical
Retail
Gaming
Hospitality
Mining
Entertainment
Oil gas
Legal services
Utilities

Targeted Countries / Regions

CN
US
UA
IN
RU
IR
JP
PK
GB
DE
TW
IL
SA
KR
KP
TR
FR
CA
AU
PL
VN
KZ
BR
ES
IT
IQ
AE
SG
NL
SY
MX
BY
AZ
RO
EG

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

CashRewindo is a sophisticated threat actor that exploits aged domains in global malvertising campaigns, steering victims toward investment‑scam sites while intermittently delivering malicious JavaScript payloads embedded within legitimate libraries. The group employs A/B testing against ad‑verification systems, switching between innocuous and call‑to‑action ads to evade detection. Their operations span multiple continents and target sectors ranging from government and defense to finance and healthcare.

Goals & Targeting

CashRewindo seeks to extract financial gains through investment‑scam funnels while simultaneously collecting intelligence from a wide spectrum of sectors. By targeting high‑profile industries such as defense, energy, transportation, and medical research across dozens of countries—including China, the United States, Ukraine, India, Russia, Iran, Japan, and many others—the actor maximizes the value of compromised data and facilitates long‑term influence operations. Typical victims include mid‑ to large‑scale organizations that rely heavily on third‑party web services and are more likely to engage with ad networks, making them attractive prey for malvertising delivery.

Enhanced Description

Key Capabilities

  • Aging domain acquisition for persistent traffic diversion
  • Drive‑by exploitation via malformed or maliciously injected JavaScript in common libraries
  • Ad content switching and A/B testing against real‑time verification systems
  • Localization of malicious payloads with regionally relevant language and imagery
  • Stealthy command‑and‑control communications using compromised web domains
  • Long‑term persistence through downloader scripts that establish backdoors
  • Use of legitimate ad network channels to obscure the true origin of malicious code

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control

ATT&CK Techniques

T1189 – Drive‑by Compromise
T1204 – User Execution
T1071.001 – Application Layer Protocol (HTTP/HTTPS) C2
T1055.001 – Process Injection

Software / Tooling

Custom JavaScript downloader scripts
Embedded malicious libraries in legitimate JS bundles
Domain‑based malvertising infrastructure

Campaigns & Victims

CashRewindo’s campaigns are initiated by placing aged domains across ad networks, then using a staged approach that first presents harmless ads to build trust before switching to malicious calls‑to‑action. The actor applies A/B testing methodology, constantly iterating on creative elements and exploiting the time window of ad verification processes. Operational tempo appears moderately high; new variants are released regularly across multiple regions, focusing on high‑value target sectors while maintaining low visibility by leveraging legitimate JavaScript libraries as a delivery vector.

IOC Patterns

  • Malvertising via aged or hijacked domains
  • Drive‑by download of malicious JavaScript embedded within commonly used libraries
  • Ad content switching between innocuous and phishing or scam calls‑to‑action
  • Localized language targeting specific geographies

Recommended Actions

  • Implement advanced web filtering capable of detecting known malvertising domains and blocking injected JS payloads
  • Deploy integrity verification (e.g., Subresource Integrity) for third‑party JavaScript libraries to detect tampering
  • Enforce strict browser security posture, including disabling or restricting execution of inline scripts
  • Maintain up‑to‑date patch management to mitigate browser and Flash vulnerabilities exploited in drive‑by attacks
  • Educate users on the risks of interacting with unexpected ads and scam offerings
  • Monitor network traffic for anomalous HTTP/S flows that may indicate hidden command‑and‑control channels

Suggested Tags

APT
Malvertising
Espionage
Financial fraud
Cybercrime

Confidence Assessment

The assessment is based primarily on a 2022 Confiant article and the group description, giving moderate confidence in the actor’s use of malvertising, aged domains, and JavaScript injection. Recent activity data, precise tool lists, and advanced persistence mechanisms are not well documented, creating gaps regarding exact capabilities and operational cadence.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. library.bsafes.com — Cited by web research for: Earth Preta
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. www.theregister.com — Cited by web research for: phishing
  4. www.theregister.com — Cited by web research for: Cobalt
  5. www.tanium.com — Cited by web research for: Context.ai

Intel Summary

4

Techniques

47

Tools

0

Campaigns

32

IOCs

0

Observed Data

1

Tactics

Tags

APT
financial fraud
malvertising
JavaScript exploit
global campaign
Malvertising
Espionage
Financial fraud
Cybercrime

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.