Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors mortar

Also known as: tracked as, caterpillar tread, tank tread, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, confusing language, brand, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Tech Sectors, Royal Ransomware, Agrius

Description

Mortar emerged as a hybrid threat actor blending ransomware delivery with espionage capabilities. Their most prominent toolset includes the Mortar Loader V3—an Office add‑in based payload that delivers shellcode into victim systems while avoiding detection through stealthy execution paths. Once compromised, victims are instrumented with the BRICKSTORM backdoor, which features a SOCKS proxy for covert command and control, as well as optional credential harvesting modules. Ransomware deployment follows a double‑extortion model: data is first exfiltrated via native OS APIs or via cloud connectors, then encrypted using an RSA‑based key or a Rust‑derived cryptographic routine. Custom ransomware variants (e.g., MORTAR or BlackSuit) modify file extensions and terminate anti‑malware services to accelerate payoff. Beyond ransomware, Mortar demonstrates supply‑chain reach—injecting malicious updates into legitimate software—and employs mobile malware such as Pineflower for surveillance in Android environments. Phishing campaigns are sophisticated, often leveraging IABs, typo‑squatted domains or phishing kits (GCollection) to deliver attachments and links. Operationally, the group relies on “living off the land” primitives (PowerShell scripts, Windows binaries like rundll32), remote desktop persistence, and Cobalt Strike for post‑exploitation movement. They target a broad spectrum of organizations with no apparent sector focus, although critical infrastructure and high‑profile commercial entities are frequent targets due to their ability to pay. Overall, Mortar’s dual threat profile—extortion plus ongoing espionage via backdoors—creates significant risks for medium‑sized enterprises that lack robust detection for Office add‑ins, RDP exfiltration, or cloud‑to‑cloud lateral movement.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Education
Manufacturing
Non profit
Critical infrastructure
Media
Energy
Hospitality
Retail
Aerospace
Pharmaceutical
Aviation
Information technology
Gaming
Transportation
Think tank
Mining
Chemical
Legal services
Nuclear
Construction
Entertainment
Maritime
Utilities
Oil gas
Food agriculture

Targeted Countries / Regions

CN
US
RU
UA
IR
GB
VN
AU
IN
JP
PK
TW
IL
SA
DE
AE
BY
SG
KR
KP
PL
CA
TR
MX
ES
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 58 chunks · 6 days ago

Executive Summary

Mortar is a financially‑motivated ransomware group that combines stealthy initial access via Office add‑ins and phishing with an espionage‑grade backdoor (BRICKSTORM) and a custom ransomware engine. The actors exploit cloud storage, supply‑chain vulnerabilities, and credential theft to exfiltrate data before encrypting victims, leveraging double‑extortion tactics to maximize revenue.

Goals & Targeting

Mortar’s strategic objective is to extract maximum financial value through ransomware while extracting data for dual extortion and potentially for longer‑term espionage. The group pursues a wide target spectrum with no clear sector bias, focusing instead on organizations offering high revenue potential or rich data assets. Through stealthy initial access techniques (phishing via Office add‑ins), rapid lateral movement, and persistent backdoors, Mortar maintains prolonged presence enabling both immediate ransom demands and delayed intel exploitation. By leveraging cloud services (OneDrive, Azure AD, Okta) they seek to exfiltrate data with minimal network visibility. Their use of custom ransomware coupled with supply‑chain attacks signals an intent to evolve defensively against patching cycles and detection systems while capitalizing on privileged access. In sum, Mortar combines short‑term ransom pressure with long‑term data extraction missions to satisfy financial motives while sustaining espionage capabilities.

Enhanced Description

Key Capabilities

  • Stealth initial access via malicious Office add‑ins
  • Phishing campaigns using attachments and IABs
  • Supply‑chain infection for backdoor deployment
  • Backdoor execution using BRICKSTORM with SOCKS proxy
  • Credential harvesting (OutSteel, GCollection, DWP)
  • Data exfiltration through native OS APIs or cloud connectors
  • Double‑extortion ransomware deployment - MORTAR, BlackSuit, BlackByte variants
  • Rust/Go based encryption engines with RSA keys
  • Mobile malware delivery (Pineflower) for surveillance
  • Living‑off‑the‑Land execution via PowerShell and Windows binaries
  • RDP persistence and lateral movement
  • Cobalt Strike utilization for post‑exploitation
  • Remote desktop tools (AnyDesk, RDP) for persistence
  • Defensive evasion: anti‑EDR, MFA bypass, keylogging & screen capture

MITRE ATT&CK Tactics

Initial Access
Execution
Command & Control
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Exfiltration
Impact
Lateral Movement

ATT&CK Techniques

T1566.001
T1566.002
T1110
T1110.001
T1110.002
T1110.003
T1110.004
T1577
T1195
T1048
T1071
T1071.001
T1071.003
T1105
T1041
T1059.003
T1136.001
T1055
T1086
T1003
T1112
T1074
T1075
T1021.001
T1021
T1021.004
T1077
T1540

Software / Tooling

Mortar Loader V3
Mortar Loader
BRICKSTORM backdoor
MORTAR ransomware
BlackSuit ransomware
BlackByte ransomware
Pineflower malware
Cobalt Strike
GootLoader
Mimikatz
PowerShell scripts
AnyDesk
Remote desktop tools

Campaigns & Victims

Mortar campaigns typically follow a rapid, double‑extortion pattern: spearphishing initiates compromise; the loader places BRICKSTORM for persistence and data theft; ransomware is then deployed on a wide range of systems—from Windows workstations to Linux servers and ESXi hosts—often in under an hour. The actor shares infrastructure with other cybercriminal RaaS groups (e.g., Akira, LockBit) through mutual backdoor libraries, suggesting operational collaboration or shared codebases. Victim profiles skew toward organizations with remote workforces leveraging cloud services, offering abundant credential vaults and backup systems that are easy to encrypt. Attackers often exploit zero‑day vulnerabilities (ProxyShell/Exchange, Log4Shell) or credential stuffing when initial access fails. The group employs a mix of waterhole sites, typo‑scattered domains, and malicious URLs bundled in phishing emails. Defensive posture reveals that incidents peak during major public events or fiscal closures, aligning with higher willingness to pay. Notable operations include the deployment of Rhysida ransomware across multiple sectors and a coordinated exfiltration followed by a Wiper payload aimed at Israeli infrastructure.

IOC Patterns

  • Spearphishing emails with malicious attachments or links
  • Phishing campaigns using IABs, typo‑squatted domains, and phishing kits
  • Malicious URLs leading to credential harvesting sites
  • Adversary-controlled domains for C2 traffic (SMTP/IMAP)
  • Backdoor binaries featuring SOCKS proxy functionality
  • Credential dumping tools like Mimikatz
  • Exfiltration indicators (data staging directories), unusual network traffic to cloud storage
  • Encrypted or obfuscated PowerShell scripts
  • Changes in registry or system configuration used for persistence
  • RDP session logs indicating lateral movement

Recommended Actions

  • Implement MFA and enforce conditional access policies on all remote services and cloud identities.
  • Deploy Office 365 Defender rules that block or sandbox new Office add‑ins, especially from untrusted origins.
  • Enable EDR with detection of stealth shellcode loaders and backdoor behavior such as SOCKS proxy use.
  • Monitor OneDrive/Office 365 activity for large outbound transfers or anomalous patterns. Maintain up‑to‑date backups in immutable media and test restore procedures before patching ransomware variants. Block known command‑and‑control domains/IPs (including Brickstorm, GootLoader, Cobalt Strike beacon traffic) via threat‑intel feeds. Apply strict application whitelisting for PowerShell and Windows binaries; monitor for lateral RDP use or AnyDesk connections. Conduct user awareness campaigns focused on spearphishing, especially phishing attachments, IABs, and link-based malware. Patch systems promptly to mitigate zero‑day exploitation vectors such as Exchange ProxyShell and Log4Shell. Detect and remove malicious Android payloads (Pineflower) via mobile threat defense solutions. Log and investigate any changes in registry or system services that could indicate backdoor persistence or anti‑malware termination.

Suggested Tags

ransomware
double-extortion
phishing
office-addins
cloud-storage
stealth-execution
mortar
brickstorm-backdoor
financial-motivation
credential-stealer
command-and-control
exfiltration
backdoor
cobalt-strike-usage
proxyshell-exploitation
wiper-malware
android-malware
rdp-lateral-movement
mfa-bypass
supply-chain-compromise

Confidence Assessment

The evidence is derived from multiple, partially overlapping sources that collectively outline Mortar’s malware toolkit, operational tactics, and attack lifecycle. While the core capabilities—Office add‑in delivery, Brickstorm backdoor, double‑extortion ransomware—are consistently reported, gaps remain regarding precise target sectors, attribution depth, and the full scope of infrastructure used. Overall confidence is moderate; ongoing monitoring and intelligence collection are essential to refine activity patterns.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. https://kpmg.com/nl/en/insights/technology-and-ai/mortar-loader-in-practice-stealth-attack-with-microsoft-office-add-ins-and-onedrive.html — Cited by AI analysis.
  2. https://www.ransomware.live/groups — Cited by AI analysis.
  3. https://www.cisa.gov/news-events/analysis-reports/ar25-338a — Cited by AI analysis.
  4. attack.mitre.org — Cited by web research for: Sandworm Team
  5. www.splunk.com — Cited by web research for: confusing language
  6. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  7. attack.mitre.org — Cited by web research for: Tech Sectors
  8. www.sentinelone.com — Cited by web research for: Singularity
  9. pmc.ncbi.nlm.nih.gov — Cited by web research for: j.jas

Intel Summary

13

Techniques

51

Tools

0

Campaigns

38

IOCs

0

Observed Data

6

Tactics

Tags

APT
ransomware
financial-sector
double-extortion
phishing
office-addins
cloud-storage
stealth-execution
mortar
brickstorm-backdoor
financial-motivation
credential-stealer
command-and-control
exfiltration
backdoor
cobalt-strike-usage
proxyshell-exploitation
wiper-malware
android-malware
rdp-lateral-movement
mfa-bypass
supply-chain-compromise

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.