Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors kirapayload

Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

Kirapayload operates a sophisticated phishing-as-a-service delivery system known as Blacksite, delivered through the Cloaked.gg cloaking platform. The kit functions as an AiTM reverse‑proxy that captures authentication tokens, session cookies, and MFA codes during live user interactions, enabling full account takeover even against MFA‑protected accounts. Cloaked.gg actively blocks traffic from major cloud hosts such as AWS, Google Cloud, and Azure, while presenting AI‑generated decoy pages to automated scanners, thereby masking malicious URLs from security instrumentation.\n\nThe actor’s toolkit includes several capabilities that enhance persistence, evasion, and impact: it abuses UAC bypass techniques for privilege escalation, leverages valid credentials (including compromised email and cloud accounts) for initial access, and creates domain accounts via net‑user commands to expand footholds in enterprise environments. It performs automated email keyword searches with MailSniper, executes endpoint denial‑of‑service attacks that exhaust system resources, and abuses cloud storage services for infrastructure acquisition and data exfiltration. Polymorphic and mutating code, together with command obfuscation and encrypted payloads, further thwarts signature‑based detection. On the offensive side, Kirapayload engages in credential dumping, phishing campaigns, and targeted DoS attacks against DNS, web, and email services to either cripple operations or coerce victim organizations. The split‑view approach ensures that security tools perceive benign traffic while victims are routed to live phishing pages designed for consumer, financial, and enterprise identity systems.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Healthcare
Government
Media
Education
Critical infrastructure
Manufacturing
Information technology
Food agriculture
Oil gas

Targeted Countries / Regions

US
AU
BR
CA
RU

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 18 hours ago

Executive Summary

Kirapayload is a financially motivated threat actor offering an Adversary‑in‑the‑Middle (AiTM) phishing-as-a-service platform, ‘Cloaked.gg’, that intercepts authentication tokens and 2FA codes in real time through a reverse‑proxy. It targets high‑profile sectors across the US, Canada, Australia, Brazil, and Russia, leveraging cloud services for infrastructure, stealth, and exfiltration. The actor combines credential theft with spoofed traffic and AI‑generated decoy pages to split view victims while evading automated detection.

Goals & Targeting

The actor’s overarching objective is monetary gain through credential theft and data exfiltration from high‑value sectors such as finance, defense, healthcare, and critical infrastructure. By offering a low‐barrier marketplace for AiTM services, Kirapayload expands its operational reach to less technically sophisticated adversaries, thereby broadening the attack surface. Targeting organizations that rely heavily on cloud services and MFA, the actor seeks to bypass conventional defenses while extracting valuable data or delivering ransomware payloads. Its targeting profile includes government agencies and public sector entities in the US, Canada, Australia, Brazil, and Russia, sectors with high reputational risk and lucrative data holdings. Kirapayload also focuses on enterprises that use Microsoft 365, Google Workspace, or other SaaS platforms where credential lateral movement is feasible.

Enhanced Description

Key Capabilities

  • UAC bypass for privilege escalation
  • Use of compromised email and cloud accounts for initial access
  • Leverage third‑party web services as command and control
  • Domain account creation via net user /add /domain
  • Valid credentials to Exchange, Office 365, or Google Workspace
  • Automated email keyword search with MailSniper
  • Endpoint denial‑of‑service attacks
  • Exploitation of software vulnerabilities for crash/lateral movement
  • Email phishing abuse
  • Cloud provider accounts acquisition
  • Polymorphic/mutating code for evasion
  • Command obfuscation and encryption

MITRE ATT&CK Tactics

Privilege Escalation
Initial Access
Exfiltration
Persistence
Credential Access
Impact
Collection
Execution
Discovery
Command and Control
Defense Evasion

ATT&CK Techniques

T1548.002
T1078
T1530
T1136
T1499
T1566.001
T1598.001
T1046
T1018
T1027
T1557

Software / Tooling

MailSniper
Cloaked.gg
Blacksite

Campaigns & Victims

Kirapayload exhibits a rapid operational tempo, often spinning up new phishing campaigns within days of registering cloud infrastructure. Its infrastructure appears modular; the actor creates multiple tenant domains in public clouds and then flips traffic through its Cloaked.gg layer to avoid detection. Victims span high‑profile enterprises with globally distributed assets – typical for organizations heavily reliant on cloud services. Past operations have surfaced a pattern where compromised accounts are leveraged for both credential harvesting and lateral movement, followed by a quick transition to ransomware or extortion narratives. Continuous use of AI‑generated decoys suggests an evolving response to automated analysis platforms.

IOC Patterns

  • Domain account creation via net user command usage
  • Credential-based access to Exchange/Office 365/Google Workspace mailboxes
  • Endpoint resource exhaustion for DoS attacks
  • Use of public cloud storage (S3, OneDrive, Dropbox) for exfiltration
  • Spoofed HTTP User‑Agent strings in traffic
  • Malicious replacement of service binaries

Recommended Actions

  • Deploy real‑time monitoring of net user /add and other domain account creation events to detect lateral expansion.
  • Enforce MFA with hardened bypass detection mechanisms (e.g., UAC bypass alerts).
  • Implement network segmentation and rate limiting for critical services to mitigate DoS impact.
  • Conduct daily credential validation checks on enterprise email and cloud accounts for abnormal access patterns.
  • Apply strict file permission controls on Windows service binaries and directories to prevent tampering.
  • Use behavioral IDS/UEBA solutions to detect polymorphic/mutating code activity.
  • Maintain up‑to‑date signatures for known phishing templates and AiTM reverse‐proxy traffic.
  • Implement application whitelisting and enforce the principle of least privilege across all endpoints.

Suggested Tags

Phishing
MFA Bypass
Adversary-in-the-Middle
Credential Theft
AI-Generated Decoy Pages
Split-View Environment
Domain Account Creation
Exchange Access
Office 365 Access
Google Workspace Access
MailSniper Tool
Denial of Service
Endpoint DoS
Polymorphism
Mutating Code

Confidence Assessment

The available data provides a solid understanding of Kirapayload’s capabilities and delivery methods, but attribution remains tentative due to limited incident‑level evidence. The actor’s operational patterns are inferred from public reports and sample IOCs; further details on infrastructure timelines, exact target lists, and attacker motivations are lacking. Consequently, confidence in threat characterization is considered moderate, with gaps in precise campaign chronology and definitive mapping of cloud resources.

ATT&CK Techniques

Exfiltration
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. attack.mitre.org — Cited by web research for: PowerShell
  3. ransomwareauthority.com — Cited by web research for: LockBit
  4. www.trmlabs.com — Cited by web research for: Critical Infrastructure
  5. https://ctid.mitre.org/projects/top-attack-techniques/ — Cited by AI analysis.

Intel Summary

49

Techniques

48

Tools

0

Campaigns

39

IOCs

0

Observed Data

13

Tactics

Tags

Phishing
Data Exfiltration
MFA Bypass
Adversary-in-the-Middle
Credential Theft
AI-Generated Decoy Pages
Split-View Environment
Domain Account Creation
Exchange Access
Office 365 Access
Google Workspace Access
MailSniper Tool
Denial of Service
Endpoint DoS
Polymorphism
Mutating Code

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
55%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.