Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors y2k operators

Also known as: tracked as, YoroTrooper, version 2.4, SnappyClient, Ghostwriter, CVE-2026-33825, Nightmare-Eclipse

Description

Y2K Operators is an opaque, financially driven cybercriminal cohort identified by Group‑IB that monetizes the Millenium remote access trojan (RAT) via a malware‑as‑a‑service model. The RAT has evolved from its .NET roots to a native C++ rewrite, embedding an obfuscated Base64 configuration within PE resources and protecting this data with a custom XOR routine. Persistence is achieved by creating a folder in %APPDATA%, authorizing a Run‑key entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and optionally installing scheduled tasks. Command and control traffic flows over the Telegram Bot API using HTTPS, with bots hosted on legitimate domains or proxy servers to conceal infrastructure. Malicious binaries—ranging from credential‑stealers such as VietCredCare/DuckTail to ransomware derivatives of LockBit and Conti—are delivered through the bot’s getUpdates endpoint and executed locally. The RAT also downloads additional payloads via the Telegram API. Defense evasion is supported by process masquerading (e.g., svchost.exe, MsEdgeUpdate.exe), disabling Windows Defender through API calls, sandbox detection to terminate execution in virtualized environments, and embedding Base64‑encoded code within resources. Data exfiltration methods rely on third‑party file hosts such as Gofile or cloud platforms, while collection capabilities span screen and audio capture, webcam logging, keylogging, browser history theft, and cryptocurrency wallet enumeration. Operated via ShinyEnigma for $50–$90 USD, Y2K Operators has infected over 62,000 unique devices across more than 160 countries, with a notable spike in March 2026 as the use of Telegram increased for both distribution and C2. The actor weaponises other tools by embedding backdoors into popular RATs and exploit kits, effectively turning other cybercriminal operations into additional infection vectors.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Manufacturing
Aviation
Media
Healthcare
Retail
Telecommunications
Utilities
Transportation
Critical infrastructure
Education
Hospitality
Energy

Targeted Countries / Regions

RU
US
SG
AU
VN
BR
CN
FR
IT
RO
EG
NL
IN
KZ
GB

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Y2K Operators is a financially motivated threat actor offering the native C++ version of the Millenium RAT as malware‑as‑a‑service, with an advertised price of $50–$90 USD. They have infected more than 62,000 Windows endpoints worldwide in early 2026 by leveraging Telegram Bot API traffic for command and control, deploying persistence through Run keys, and exfiltrating data via third‑party hosts such as Gofile. The group’s attacks target a wide array of sectors—including finance, defense, government, healthcare, energy, and critical infrastructure—across more than 160 countries using social engineering that masquerades malicious payloads as legitimate or cracked software.

Goals & Targeting

Y2K Operators seeks to maximize financial gain by commoditising remote access capabilities and ransomware payloads at a low cost, thereby enabling a wide pool of opportunistic actors. Their targeting breadth includes high‑value sectors such as finance, defense, government, healthcare, energy, and critical infrastructure, spanning the United States, Russia, China, Europe, South America, Southeast Asia, and Oceania. By distributing malware disguised as legitimate or cracked software and exploiting Telegram’s widespread usage for covert command channels, Y2K Operators is able to acquire credentials, exfiltrate sensitive data, and deploy ransomware at scale.

Enhanced Description

Key Capabilities

  • Persistence through HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry entries
  • Command & Control via Telegram Bot API over HTTPS without dedicated servers
  • Remote system disruption (shutdown/reboot/hibernate/BSOD/logoff)
  • Data exfiltration to third‑party file hosts such as Gofile or cloud storage services
  • Collection of victim data: username, browser history, cryptocurrency wallet extensions, IP geolocation, webcam capture, screen and audio capture, keylogging
  • Remote access and control via the native C++ Millenium RAT
  • Download and execution of arbitrary executables obtained through Telegram getUpdates API
  • Social engineering via masquerading malicious payloads as legitimate or cracked software
  • Embedding backdoors into popular RATs, builders, and exploit kits

MITRE ATT&CK Tactics

Persistence
Discovery
Collection
Command and Control
Exfiltration
Impact
Initial Access
Execution
Defense Evasion

ATT&CK Techniques

T1547.001
T1217
T1614
T1033
T1005
T1125
T1071.001
T1567.002
T1529
T1056.001
T1113
T1041
T1204
T1036
T1059.001

Software / Tooling

Millennium RAT v4.*
ShinyEnigma
VietCredCare
DuckTail
XWorm builder trojanised
Phoenix System

Campaigns & Victims

Y2K Operators has executed large‑scale campaigns beginning in mid‑2025, with a dramatic acceleration in March 2026. Their malware‑as‑a‑service offering attracts low‑budget operators worldwide, resulting in over 62,000 infections across more than 160 countries in just a few months. The organization distributes the RAT primarily through social engineering attacks that present malicious payloads as legitimate or cracked software, and it leverages Telegram Bot API traffic for covert command and control, reducing reliance on dedicated infrastructure. Victims span critical sectors such as finance, defense, healthcare, energy, and transportation, indicating a strategy of high‑value data exfiltration and opportunistic ransomware deployment.

IOC Patterns

  • Registry Run key persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run
  • Telegram Bot API traffic over HTTPS
  • Data exfiltration via file hosting services such as Gofile
  • Remote shutdown/restart/hibernate/BSOD commands
  • Compressed archives or disguised executables with enticing filenames for delivery
  • Masquerading of malicious payloads as legitimate software or cracked applications
  • Embedding backdoors into third‑party RATs, builders, and exploit kits

Recommended Actions

  • Monitor and block outbound Telegram Bot API traffic to non‑authorized destinations.
  • Detect, alert on, and remediate new Run key entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run.
  • Deploy endpoint detection and response solutions that identify Millennium RAT signatures and behaviors.
  • Implement application whitelisting or sandboxing for downloads of compressed archives and disguised executables.
  • Block outbound traffic to known third‑party file hosting services such as Gofile unless explicitly approved.
  • Enforce least privilege policies to restrict capabilities to trigger remote shutdown or reboot.

Suggested Tags

y2k operators
millennium rat
telegram bot c2
persistence run key
exfiltration via google drive equivalents
remote system disruption
phishing as a service
c2 over https
malware instrumentation of other tools
rat
maaS
social engineering
masquerading

Confidence Assessment

Confidence in the overall picture is high, based on multiple independent reports from Group‑IB and Infosecurity magazine. Core details—such as the use of a native C++ Millenium RAT, Telegram‑based command and control, and large‑scale infections—are well corroborated. However, gaps remain in precise timelines (first/last seen), internal structure, attribution to nation‑state actors, and exact distribution mechanisms beyond social engineering fronts.

ATT&CK Techniques

Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 13 Domain 2 URL 4 IPv4 Address 1

References

  1. https://www.group-ib.com/blog/millenium-rat-maas/ — Cited by AI analysis.
  2. https://seyhan.biz/millenium-rat-rewritten-in-c-infects-62000-devices-across-160-countries/ — Cited by AI analysis.
  3. https://cybersecuritynews.com/millenium-rat-rewritten-in-c/ — Cited by AI analysis.
  4. https://infosecurity-magazine.com/news/millenium-rat-telegram-60000/ — Cited by AI analysis.
  5. https://www.infosecurity-magazine.com/news/millenium-rat-telegram-60000/ — Cited by AI analysis.
  6. www.group-ib.com — Cited by web research for: YoroTrooper
  7. thehackernews.com — Cited by web research for: Proton
  8. www.probablypwned.com — Cited by web research for: Stealc
  9. cyberinsider.com — Cited by web research for: Guard

Intel Summary

42

Techniques

59

Tools

0

Campaigns

39

IOCs

0

Observed Data

11

Tactics

Tags

RAT
MaaS
Social Engineering
Global Threat
Y2K Operators
Millenium RAT
Group-IB
Remote Access Trojan
Telegram C2
Social Engineering Delivery
Malware-as-a-Service
Keylogging
Screenshot Capture
Audio Capture
Cryptocurrency Theft
Persistence via Registry Run Key
Phishing
Credential Theft
Backdoor Injection
Masquerading
Defense Evasion
y2k operators
millennium rat
telegram bot c2
persistence run key
exfiltration via google drive equivalents
remote system disruption
phishing as a service
c2 over https
malware instrumentation of other tools
rat
maaS
social engineering
masquerading

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Jul 25, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.