Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
Kirapayload operates a sophisticated phishing-as-a-service delivery system known as Blacksite, delivered through the Cloaked.gg cloaking platform. The kit functions as an AiTM reverse‑proxy that captures authentication tokens, session cookies, and MFA codes during live user interactions, enabling full account takeover even against MFA‑protected accounts. Cloaked.gg actively blocks traffic from major cloud hosts such as AWS, Google Cloud, and Azure, while presenting AI‑generated decoy pages to automated scanners, thereby masking malicious URLs from security instrumentation.\n\nThe actor’s toolkit includes several capabilities that enhance persistence, evasion, and impact: it abuses UAC bypass techniques for privilege escalation, leverages valid credentials (including compromised email and cloud accounts) for initial access, and creates domain accounts via net‑user commands to expand footholds in enterprise environments. It performs automated email keyword searches with MailSniper, executes endpoint denial‑of‑service attacks that exhaust system resources, and abuses cloud storage services for infrastructure acquisition and data exfiltration. Polymorphic and mutating code, together with command obfuscation and encrypted payloads, further thwarts signature‑based detection. On the offensive side, Kirapayload engages in credential dumping, phishing campaigns, and targeted DoS attacks against DNS, web, and email services to either cripple operations or coerce victim organizations. The split‑view approach ensures that security tools perceive benign traffic while victims are routed to live phishing pages designed for consumer, financial, and enterprise identity systems.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Kirapayload is a financially motivated threat actor offering an Adversary‑in‑the‑Middle (AiTM) phishing-as-a-service platform, ‘Cloaked.gg’, that intercepts authentication tokens and 2FA codes in real time through a reverse‑proxy. It targets high‑profile sectors across the US, Canada, Australia, Brazil, and Russia, leveraging cloud services for infrastructure, stealth, and exfiltration. The actor combines credential theft with spoofed traffic and AI‑generated decoy pages to split view victims while evading automated detection.
Goals & Targeting
The actor’s overarching objective is monetary gain through credential theft and data exfiltration from high‑value sectors such as finance, defense, healthcare, and critical infrastructure. By offering a low‐barrier marketplace for AiTM services, Kirapayload expands its operational reach to less technically sophisticated adversaries, thereby broadening the attack surface. Targeting organizations that rely heavily on cloud services and MFA, the actor seeks to bypass conventional defenses while extracting valuable data or delivering ransomware payloads. Its targeting profile includes government agencies and public sector entities in the US, Canada, Australia, Brazil, and Russia, sectors with high reputational risk and lucrative data holdings. Kirapayload also focuses on enterprises that use Microsoft 365, Google Workspace, or other SaaS platforms where credential lateral movement is feasible.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Kirapayload exhibits a rapid operational tempo, often spinning up new phishing campaigns within days of registering cloud infrastructure. Its infrastructure appears modular; the actor creates multiple tenant domains in public clouds and then flips traffic through its Cloaked.gg layer to avoid detection. Victims span high‑profile enterprises with globally distributed assets – typical for organizations heavily reliant on cloud services. Past operations have surfaced a pattern where compromised accounts are leveraged for both credential harvesting and lateral movement, followed by a quick transition to ransomware or extortion narratives. Continuous use of AI‑generated decoys suggests an evolving response to automated analysis platforms.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a solid understanding of Kirapayload’s capabilities and delivery methods, but attribution remains tentative due to limited incident‑level evidence. The actor’s operational patterns are inferred from public reports and sample IOCs; further details on infrastructure timelines, exact target lists, and attacker motivations are lacking. Consequently, confidence in threat characterization is considered moderate, with gaps in precise campaign chronology and definitive mapping of cloud resources.
No campaigns linked yet.
No observed data linked yet.
49
Techniques
48
Tools
0
Campaigns
39
IOCs
0
Observed Data
13
Tactics