Also known as: tracked as, Charming Kitten, ESET said, Newscaster, Parastoo, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, NEWSCASTER, APT35, RICH ION
Titan emerged in early 2026, quickly establishing itself as a financially driven criminal collective with ambitions that span ransomware payouts to covert intelligence gathering. Their operational model relies on a blend of social engineering—primarily spear‑phishing—and exploitation of known vulnerabilities, notably the unauthenticated template injection (CVE‑2023‑22527) in Atlassian Confluence and network device weaknesses like Check Point IKEv1 CVE‑2026‑50751 and ConnectWise ScreenConnect CVE‑2024‑1708. Once a foothold is gained, attackers deploy custom binaries such as *titan‑edge* and *libgoworkerd.so*, manipulate environment variables (e.g., misspelled LD_LIBRARY_PATH) and SSH authorized_keys to achieve persistence and evade detection. Beyond traditional RCE, Titan’s post‑compromise activities include dynamic linker hijacking for privilege escalation, binding compromised hosts to an attacker‑controlled ID on a DePIN network where they initiate cryptomining operations using the aleo‑pool client. They also stage large volumes of data in temporary directories before proceeding with ransomware encryption, often extracting engineering designs or other high‑value intelligence from government and defense contractors. Titan’s toolkit is modular: shell scripts automate download and execution; custom TLS‑based command & control channels use web protocols (T1071.001), while remote management tools such as ConnectWise ScreenConnect are exploited to establish lateral movement paths. Their campaigns demonstrate a consistent pattern of leveraging high‑impact CVEs, coupling them with stealthy persistence layers that can remain active for extended periods before triggering ransomware payloads.
Fake Social Media Account
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Titan is a medium‑sophistication threat actor that combines ransomware, cryptomining and espionage capabilities to target both commercial and defense organizations worldwide. They exploit unpatched public applications such as Atlassian Confluence and Check Point gateways, then implant persistent backdoors configured for wide‑scale data staging and eventual encryption of critical assets.
Goals & Targeting
Titan’s strategic objectives blend immediate financial gain from ransom payments and cryptomining revenue with longer‑term espionage gains. By targeting sectors such as government, defense, finance, healthcare, media, critical infrastructure, and telecommunications across a broad geographic footprint—especially the US, Ukraine, Russia, and Israel—they aim to compromise high-visibility platforms for both monetary extraction and information theft. The actor’s use of spear‑phishing and exploitation of well-known open‑source or vendor‑supplied software underlines their intent to maximize attack surface while minimizing effort.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Titan’s earliest campaign, dubbed "Mezta Corporativo," leveraged a known CVE in Atlassian Confluence to deploy ransomware against a manufacturing client, while subsequent operations named after industries (e.g., "DFI AMERICA" and "Groupe CRIT SA") demonstrate methodical expansion into finance, defense and media. The actor typically conducts brief but intense action windows—often within 24–48 hours of initial access—to stage data in temporary folders, exfiltrate targets of strategic interest, and deploy ransomware before cleaning up traces or shifting to mining operations. Their repeated exploitation of vendor CVEs indicates a focus on high-value attacks that require minimal development effort yet yield significant financial returns. Notably, Titan’s use of cryptomining via DePIN nodes signals an evolution from pure ransomware to hybrid financially-driven operations, providing diversified revenue streams while maintaining the option for covert data gathering from state or critical infrastructure networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a moderately high confidence view of Titan’s capabilities and objectives, corroborated by documented CVE exploitation and observed ransomware deployments across diverse sectors. However, gaps remain regarding the full extent of their infrastructure, attribution certainty beyond the Chinese state actor label, and detailed operational tempo for future campaigns. Continuous monitoring and threat hunting are recommended to close these knowledge gaps.
titan: DataOstrov s.r.o.
Ransomware attack attributed to titan. | Country: CZ | Sector: Technology | [AI generated] N/A | Source: https://www.ransomware.live/id/RGF0YU9zdHJvdiBzLnIuby5AdGl0YW4=
Jul 13, 2026
TLP:CLEARNo observed data linked yet.
12
Techniques
56
Tools
15
Campaigns
43
IOCs
0
Observed Data
6
Tactics