Also known as: tracked as, YoroTrooper, version 2.4, SnappyClient, Ghostwriter, CVE-2026-33825, Nightmare-Eclipse
Y2K Operators is an opaque, financially driven cybercriminal cohort identified by Group‑IB that monetizes the Millenium remote access trojan (RAT) via a malware‑as‑a‑service model. The RAT has evolved from its .NET roots to a native C++ rewrite, embedding an obfuscated Base64 configuration within PE resources and protecting this data with a custom XOR routine. Persistence is achieved by creating a folder in %APPDATA%, authorizing a Run‑key entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and optionally installing scheduled tasks. Command and control traffic flows over the Telegram Bot API using HTTPS, with bots hosted on legitimate domains or proxy servers to conceal infrastructure. Malicious binaries—ranging from credential‑stealers such as VietCredCare/DuckTail to ransomware derivatives of LockBit and Conti—are delivered through the bot’s getUpdates endpoint and executed locally. The RAT also downloads additional payloads via the Telegram API. Defense evasion is supported by process masquerading (e.g., svchost.exe, MsEdgeUpdate.exe), disabling Windows Defender through API calls, sandbox detection to terminate execution in virtualized environments, and embedding Base64‑encoded code within resources. Data exfiltration methods rely on third‑party file hosts such as Gofile or cloud platforms, while collection capabilities span screen and audio capture, webcam logging, keylogging, browser history theft, and cryptocurrency wallet enumeration. Operated via ShinyEnigma for $50–$90 USD, Y2K Operators has infected over 62,000 unique devices across more than 160 countries, with a notable spike in March 2026 as the use of Telegram increased for both distribution and C2. The actor weaponises other tools by embedding backdoors into popular RATs and exploit kits, effectively turning other cybercriminal operations into additional infection vectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Y2K Operators is a financially motivated threat actor offering the native C++ version of the Millenium RAT as malware‑as‑a‑service, with an advertised price of $50–$90 USD. They have infected more than 62,000 Windows endpoints worldwide in early 2026 by leveraging Telegram Bot API traffic for command and control, deploying persistence through Run keys, and exfiltrating data via third‑party hosts such as Gofile. The group’s attacks target a wide array of sectors—including finance, defense, government, healthcare, energy, and critical infrastructure—across more than 160 countries using social engineering that masquerades malicious payloads as legitimate or cracked software.
Goals & Targeting
Y2K Operators seeks to maximize financial gain by commoditising remote access capabilities and ransomware payloads at a low cost, thereby enabling a wide pool of opportunistic actors. Their targeting breadth includes high‑value sectors such as finance, defense, government, healthcare, energy, and critical infrastructure, spanning the United States, Russia, China, Europe, South America, Southeast Asia, and Oceania. By distributing malware disguised as legitimate or cracked software and exploiting Telegram’s widespread usage for covert command channels, Y2K Operators is able to acquire credentials, exfiltrate sensitive data, and deploy ransomware at scale.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Y2K Operators has executed large‑scale campaigns beginning in mid‑2025, with a dramatic acceleration in March 2026. Their malware‑as‑a‑service offering attracts low‑budget operators worldwide, resulting in over 62,000 infections across more than 160 countries in just a few months. The organization distributes the RAT primarily through social engineering attacks that present malicious payloads as legitimate or cracked software, and it leverages Telegram Bot API traffic for covert command and control, reducing reliance on dedicated infrastructure. Victims span critical sectors such as finance, defense, healthcare, energy, and transportation, indicating a strategy of high‑value data exfiltration and opportunistic ransomware deployment.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the overall picture is high, based on multiple independent reports from Group‑IB and Infosecurity magazine. Core details—such as the use of a native C++ Millenium RAT, Telegram‑based command and control, and large‑scale infections—are well corroborated. However, gaps remain in precise timelines (first/last seen), internal structure, attribution to nation‑state actors, and exact distribution mechanisms beyond social engineering fronts.
No campaigns linked yet.
No observed data linked yet.
42
Techniques
59
Tools
0
Campaigns
39
IOCs
0
Observed Data
11
Tactics