Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ModernStealer

Also known as: other aliases, Jumpy Pisces, several other aliases, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, COLD RELIC, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, the ALPHV Ransomware Group, ALPHV Blackcat, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, APT28, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene, Velvet Chollima, Sparkling Pisces, HIDDEN COBRA, ZINC, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, STONE PANDA, Menupass Team, happyyongzi, POTASSIUM, CVNX, HOGFISH, Cloud Hopper, BRONZE RIVERSIDE, ATK41, G0045, Granite Taurus, TA429, Cicada, Purple Typhoon, VIXEN PANDA, Ke3Chang, Playful Dragon, Metushy, Lurid, Social Network Team, Royal APT, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, NICKEL, G0004, Red Vulture, Nylon Typhoon, Mirage, RIVER CASTLE

Description

ModernStealer has been traced to underground forums where it offers classified military, government, aerospace, and nuclear data for sale. Analysts have linked the group’s activity through a common Session contact identifier and its presence on Telegram in an account named Sassoon Don, indicating coordinated operations across multiple aliases such as APT37, MuddyWater, and ALPHV. The actor routinely employs sophisticated banking trojans—most notably IcedID (BokBot)—to harvest credentials before distributing them to ransomware affiliates that use the stolen accounts to execute large‑scale attacks. At the initial foothold stage, ModernStealer relies heavily on spear‑phishing, watering holes targeted at South Korean and other governmental entities, and the exploitation of Android spyware components to bypass security controls. The group’s downloader families—Latrodectus and Lotus—deploy PowerShell backdoors that facilitate persistence and remote command execution while blending into normal system activity. By combining fileless techniques with extensive post‑exploitation frameworks such as Brute Ratel and Cobalt Strike, ModernStealer can propagate laterally through complex enterprise networks. ModernStealer’s operations are not limited to credential acquisition; the actor also engages in supply‑chain compromises that threaten intellectual property theft and critical infrastructure stability. Recent analyses suggest a pattern of leveraging cloud infrastructures for command and control as well as data exfiltration, thereby increasing resilience against traditional endpoint defenses.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Healthcare
Telecommunications
Critical infrastructure
Media
Education
Manufacturing
Aerospace
Energy
Nuclear
Hospitality
Retail
Non profit
Maritime
Gaming
Information technology
Aviation
Transportation
Think tank
Legal services
Utilities
Entertainment
Food agriculture
Construction

Targeted Countries / Regions

RU
CN
IR
IN
KP
US
UA
BR
GB
KR
DE
TR
VN
PK
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

ModernStealer is a highly sophisticated threat actor that infiltrates organizations across a wide spectrum of industries, from government and defense to finance and healthcare. Leveraging a combination of banking trojans, downloader families, phishing campaigns, and ransomware affiliates, ModernStealer focuses primarily on financial gain while also extracting strategic intelligence. Its operations demonstrate advanced post‑exploitation techniques, fileless persistence, and supply‑chain compromise capabilities that enable widespread lateral movement.

Goals & Targeting

ModernStealer’s strategic objectives appear twofold: (1) financial exploitation through ransomware payouts and the sale of compromised credentials; and (2) intelligence gathering from defense, aerospace, and critical infrastructure sectors. The group targets a broad geographical footprint—primarily Russia, China, Iran, India, and the United States—while selectively focusing on high‑value organizations such as ministries of defense, state‑owned enterprises, educational institutions, and NGOs involved in research and development. By blending stealthy delivery mechanisms with disruptive ransomware tactics, ModernStealer seeks to maximize impact while minimizing attribution risk.

Enhanced Description

Key Capabilities

  • Developing and deploying banking trojans such as IcedID (BokBot)
  • Distributing downloader and loader families like Latrodectus and Lotus
  • Using phishing campaigns to acquire credentials
  • Equipping ransomware affiliates through stolen credentials
  • Deploying post‑exploitation frameworks including Brute Ratel and Cobalt Strike
  • Executing spear‑phishing attacks against governments, academia, telecoms, NGOs
  • Leveraging PowerShell‑based backdoors for persistence and command execution
  • Exploiting Android spyware capabilities
  • Conducting watering hole attacks on South Korean targets
  • Utilizing supply chain compromises to threaten intellectual property theft
  • Employing fileless malware techniques for stealthy intrusion

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Credential Access
Persistence
Privilege Escalation
Defense Evasion
Exfiltration

ATT&CK Techniques

T1037
T1059
T1059.001
T1071
T1087
T1092
T1098
T1110
T1115
T1119
T1123
T1133
T1134
T1190
T1195
T1197
T1580
T1583
T1586
T1589
T1595
T1612
T1619
T1526
T1531
T1538
T1547
T1548
T1554
T1557
T1560
T1566.001
T1566.002
T1567
T1650
T1651
T1657
T1671

Software / Tooling

IcedID (BokBot)
Latrodectus downloader
Lotus loader family
Brute Ratel
Cobalt Strike
BlackCat
Akira
Royal
BloodHound
Mythic
PowerShell
Rhadamanthys
Dark
LockBit
BianLian
Hook
Nexus
BlackSuit
Interception
Leverage
Custom malware
Ransomware variants
Jackal
Lynx
PLAY
STOP
Telegram
GitHub
BITS
Trojan
Wicked

Campaigns & Victims

ModernStealer operates on a multi‑stage, high‑tempo campaign model. Initial infections are typically seeded through spear‑phishing emails or watering holes that deliver downloaders such as Latrodectus and Lotus. Once established, the actor deploys banking trojans to harvest credentials, which are then sold to ransomware affiliates. Subsequent stages leverage powerful post‑exploitation suites—especially Brute Ratel and Cobalt Strike—to pivot laterally, elevate privileges, and exfiltrate data via alternative protocols and cloud storage services. The group’s campaigns have exhibited a strong focus on government, defense, critical infrastructure, and high‑value intellectual property while maintaining operational overlap with other aliases like APT37 and ALPHV.

IOC Patterns

  • domain
  • file
  • hash

Recommended Actions

  • Implement robust multi‑factor authentication across all accounts to safeguard against credential theft
  • Deploy email filtering and anti‑phishing solutions to detect and block spear‑phishing attempts
  • Patch known software vulnerabilities promptly, especially in asset management and web‑exposed services
  • Use EDR platforms to monitor for downloader families such as IcedID, Latrodectus, and Lotus
  • Apply network segmentation and micro‑segmentation to contain lateral movement from post‑exploitation tools like Cobalt Strike
  • Isolate or quarantine devices exhibiting fileless malware behaviors until fully cleansed

Suggested Tags

banking trojan
ransomware affiliate
phishing
spear-phishing
PowerShell backdoor
Android spyware
watering hole
supply chain compromise
fileless malware
credential harvesting

Confidence Assessment

The evidence linking ModernStealer to banking trojans, downloader families, phishing campaigns and ransomware affiliate distribution is strong, drawn from multiple independent threat reports and observed IOC patterns. However, the precise attribution pathways between its numerous aliases remain partially conjectural due to limited publicly disclosed incident data. Overall confidence in the actor’s operational capabilities and strategic targets is medium‑high, while missing timeline details and definitive motive statements introduce some uncertainty.

ATT&CK Techniques

Privilege Escalation
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 12 Filename 7 MD5 Hash 1

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. unit42.paloaltonetworks.com — Cited by web research for: T1486
  3. attack.mitre.org — Cited by web research for: T1580
  4. redcanary.com — Cited by web research for: BloodHound
  5. unit42.paloaltonetworks.com — Cited by web research for: management.azure.com
  6. https://login.microsoftonline.com — Cited by AI analysis.
  7. https://TEMP.Hermit — Cited by AI analysis.
  8. https://TEMP.Zagros — Cited by AI analysis.

Intel Summary

44

Techniques

65

Tools

7

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

banking trojan
ransomware affiliate
phishing
spear-phishing
PowerShell backdoor
Android spyware
watering hole
supply chain compromise
fileless malware
credential harvesting

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.