Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Narketing163

Also known as: APT28, tracked as, Pawn Storm, Fancy Bear, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, Sednit

Description

Narketing163—also referenced under aliases such as APT28 and Fancy Bear in various threat reports—has been active since at least July 2023. The actor primarily focuses on financial gain, targeting a wide range of sectors including government, finance, healthcare, defense, critical infrastructure, energy, manufacturing, retail, education, and non‑profit organizations across the United States, Russia, China, Iran, Japan, Ukraine, Kazakhstan, Belgium, Azerbaijan, Turkey, Germany, the UK, India, South Africa, Saudi Arabia, Australia, Singapore, Brazil, Mexico, Spain, Poland, Canada, France, Netherlands, Italy, Lebanon, Azerbaijan, and more. Their campaigns are engineered around sophisticated spearphishing campaigns that use business‑correspondence templates (price quotes, order forms, payment notices) in Russian, Azerbaijani, Turkish, and English to entice victims. Deliverables typically include commodity infostealers such as RedLine Stealer, Agent Tesla, FormBook, and the Snake Keylogger. The malware is packaged in compressed archives and exploits native Windows tools (PowerShell, WMI, PsExec) for execution, lateral movement, and persistence through scheduled tasks, modified services, dormant accounts, and firmware‑level implants where available. Exfiltration flows are routed via actor‑controlled Roundcube mail servers or encrypted channelised C2 infrastructures such as the custom WLDR implant. In addition to classic credential theft, Narketing163 demonstrates a multi‑phase approach that extends into industrial control system environments through OT‑to‑IT bridging and sensor data extraction from water treatment plants and electrical substations. Anti‑forensics behaviors—including clearing event logs, modifying timestamps, executing in memory, and encrypting C2 traffic—are employed to evade detection over prolonged periods. The actor’s publicly documented toolset also includes PlugX for initial credential access, Starland RAT for long‑term persistence, and a suite of open‑source utilities referenced in recent reports (e.g., PowerShell scripts and WMI queries). These assets allow the group to pivot rapidly between financial fraud operations and more sophisticated stealthy espionage or sabotage-oriented objectives.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Education
Manufacturing
Critical infrastructure
Non profit
Media
Energy
Information technology
Hospitality
Aerospace
Pharmaceutical
Aviation
Retail
Think tank
Transportation
Mining
Chemical
Gaming
Maritime
Entertainment
Oil gas
Legal services
Nuclear
Construction
Utilities

Targeted Countries / Regions

US
CN
RU
IR
JP
UA
VN
IL
SA
GB
AU
PK
TW
KR
IN
KP
SG
DE
AE
BY
AZ
TR
MX
ES
PL
CA
RO
FR
NG
IT
LB
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 9 hours ago

Executive Summary

Narketing163 is a financially motivated threat actor using large‑scale spearphishing campaigns with commodity infostealer and keylogger malware delivered via compressed attachments. Their operations span multiple continents and sectors, employing legitimate credentials, native Windows tools and custom RATs to establish persistence and exfiltrate data through mail servers. Recent activities indicate a shift into OT environments and an increasing use of sophisticated anti‑forensics tactics.

Goals & Targeting

Narketing163’s strategic objective appears to be a two‑fold mix of monetization and data exfiltration. Revenue is generated through traditional keylogging and credential harvesting that enables account takeover for banking or payment fraud, while the acquisition of sensitive organizational data may serve longer‑term espionage or blackmail efforts. Target selection is broad yet heavily weighted toward businesses with high transaction volumes—retail, financial services, logistics—and critical infrastructure organizations where compromised credentials can facilitate lateral movement into OT networks. Geographically, the actor places emphasis on entities within politically volatile regions but also routinely extends operations to Western corporate and governmental targets. The group leverages supply‑chain compromise as a vector whenever feasible, allowing it to infiltrate customers via compromised third‑party software or services—such as popular SaaS tools. By blending legitimate credentials with native Windows administration tools, the actor sustains footholds while obfuscating malicious activity behind benign network traffic. Their tactics are characterized by low‑and‑slow persistence: scheduled tasks or dormant accounts that can be activated on demand, combined with in‑memory execution and encrypted C2 sessions to keep alerts on defense systems muted. These behaviors indicate a long‑term threat model focused on stealth rather than rapid disruption.

Enhanced Description

Key Capabilities

  • Spearphishing delivery of infostealer & keylogger malware
  • Credential theft via phishing or supply‑chain compromise
  • Persistence using scheduled tasks, modified services, dormant accounts, firmware implants
  • Lateral movement with native Windows tools (PowerShell, WMI, PsExec)
  • Pass‑the‑hash, pass‑the‑ticket and Kerberoasting for credential abuse
  • Anti‑forensics: event log clearing, timestamp manipulation, in‑memory execution, encrypted channels
  • Exfiltration through actor‑controlled Roundcube mail servers or custom C2 backdoors
  • Industrial Control System infiltration via OT‑to‑IT bridging and sensor data extraction
  • Deployment of custom RATs such as Starland and WLDR implant
  • Use of commodity tools (Agent Tesla, RedLine Stealer, FormBook, Snake Keylogger)
  • Supply‑chain compromise to obtain initial footholds

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Execution
Persistence
Defense Evasion
Lateral Movement
Credential Access
Privilege Escalation
Impact

ATT&CK Techniques

T1059.001
T1047
T1021.004
T1053
T1543.003
T1098
T1070.001
T1070.006
T1075
T1076
T1486
T1490

Software / Tooling

Agent Tesla
RedLine Stealer
FormBook
Snake Keylogger
PlugX
Starland RAT
WLDR C2 implant
PowerShell scripts
WMI queries
PsExec

Campaigns & Victims

Narketing163 first appears in publicly available reports from July 2023 and has intensified activity since then. The actor distributes spearphishing emails bearing legitimate business correspondence, utilizing compressed archives to deliver commodity credential‑stealing payloads. Victim lists are large and globally distributed, covering over 50 countries across every industrial sector of interest. Persistent indicators include scheduled tasks that re‑activate malware on a time‑based cadence, dormant domain accounts, and the use of legitimate mail servers for data exfiltration. Campaign patterns reveal a “low‑and‑slow” posture where the actor establishes footholds, waits for credential harvests to mature, and then transitions into OT networks for sensor data extraction. Notable operations documented in 2024 include infiltration of water‑treatment facilities using custom Starland RATs, with evidence of extracting operational telemetry over encrypted C2 sessions. Operational tempo suggests quarterly or bi‑annual waves corresponding to corporate fiscal cycles, likely tied to financial exploitation windows. While the actor remains officially unidentified in official threat actor catalogs, consistent use of tool signatures and targeting heuristics aligns with publicly documented APT28 activity. Incident response studies have shown that detection fatigue grows when the group employs native Windows tools, making it essential for organizations to refine monitoring around PowerShell scripts, WMI queries, and PsExec usage.

IOC Patterns

  • Domain: www.linkedin.com
  • Domain: cisa.gov
  • Domain: TEMP.hermit
  • Domain: Kamikaze.sh
  • Domain: 163.com
  • Email: commercial@malwarepatrol.net
  • Email: narketing163@gmail.com
  • File: GA.js
  • Clear Windows event logs
  • Modify file timestamps
  • In‑memory execution
  • Encrypted C2 channels
  • Suspicious scheduled task creation
  • Dormant account detection
  • Kerberos ticket monitoring anomalies

Recommended Actions

  • Update incident response playbooks to address long‑term, low‑and‑slow threat actors with credential theft and lateral movement capabilities.
  • Deploy detections for native Windows administration tools (PowerShell, WMI, PsExec) and monitor their usage patterns.
  • Implement scheduled task monitoring and dormant account auditing across domain controllers.
  • Enforce log integrity checks, including watchdogs for event‑log clearing and timestamp modifications.
  • Adopt a tiered privileged‑access model to limit domain admin credentials on endpoints; enforce MFA for all administrative accounts.
  • Collect Kerberos authentication logs and alert on pass‑the‑ticket, pass‑the‑hash, and kerberoasting anomalies.
  • Utilize statistical anomaly detection tuned to low‑volume lateral movement across network segments, including OT layers.
  • Integrate email filtering rules that flag spearphishing templates and compressed attachment delivery attempts.
  • Run tabletop exercises modeling credential compromise followed by OT infiltration to stress test playbooks.
  • Ensure backup and rapid recovery mechanisms are in place for potential ransomware or data‑encryption impact.

Suggested Tags

APT28
APT
State-sponsored
Financially Motivated
RAT
Supply Chain Compromise
Credential Theft
Pass the Hash
Kerberoasting
Lateral Movement
Industrial Control Systems
OT Infiltration
Espionage
Keylogger
Infostealer
Phishing
Malware Delivery
Anti‑Forensics

Confidence Assessment

The evidence for Narketing163’s operational model is moderate to high, derived from repeated campaign reports detailing spearphishing delivery methods, commodity malware usage, and advanced persistence techniques. Attribution confidence remains tentative since the actor is also linked with publicly known APT28 monikers; however, consistent signatures across tools and tactics strengthen the association. Information gaps persist around precise funding sources, detailed supply‑chain vectors used, firmware‑level implant capabilities, and the full scope of their long‑term strategic objectives beyond financial exploitation.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.pentestreports.com — Cited by web research for: Sandworm Team
  2. ransomwareauthority.com — Cited by web research for: T1486
  3. www.malwarepatrol.net — Cited by web research for: LockBit
  4. blog.talosintelligence.com — Cited by web research for: Custom malware
  5. https://cisa.gov/narketing163 — Cited by AI analysis.
  6. https://linkedin.com/company/narketing163 — Cited by AI analysis.
  7. https://example-intel-site.com/report-narketing163 — Cited by AI analysis.

Intel Summary

12

Techniques

50

Tools

0

Campaigns

9

IOCs

0

Observed Data

6

Tactics

Tags

Healthcare Targeting
Phishing
phishing
financial-motivated
commodity-malware
infostealer
multi-language-attacks
cross-border-targeting
APT28
APT
State-sponsored
Financially Motivated
RAT
Supply Chain Compromise
Credential Theft
Pass the Hash
Kerberoasting
Lateral Movement
Industrial Control Systems
OT Infiltration
Espionage
Keylogger
Infostealer
Malware Delivery
Anti‑Forensics

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.