Also known as: other aliases, Jumpy Pisces, several other aliases, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, COLD RELIC, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, the ALPHV Ransomware Group, ALPHV Blackcat, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, APT28, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene, Velvet Chollima, Sparkling Pisces, HIDDEN COBRA, ZINC, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, STONE PANDA, Menupass Team, happyyongzi, POTASSIUM, CVNX, HOGFISH, Cloud Hopper, BRONZE RIVERSIDE, ATK41, G0045, Granite Taurus, TA429, Cicada, Purple Typhoon, VIXEN PANDA, Ke3Chang, Playful Dragon, Metushy, Lurid, Social Network Team, Royal APT, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, NICKEL, G0004, Red Vulture, Nylon Typhoon, Mirage, RIVER CASTLE
ModernStealer has been traced to underground forums where it offers classified military, government, aerospace, and nuclear data for sale. Analysts have linked the group’s activity through a common Session contact identifier and its presence on Telegram in an account named Sassoon Don, indicating coordinated operations across multiple aliases such as APT37, MuddyWater, and ALPHV. The actor routinely employs sophisticated banking trojans—most notably IcedID (BokBot)—to harvest credentials before distributing them to ransomware affiliates that use the stolen accounts to execute large‑scale attacks. At the initial foothold stage, ModernStealer relies heavily on spear‑phishing, watering holes targeted at South Korean and other governmental entities, and the exploitation of Android spyware components to bypass security controls. The group’s downloader families—Latrodectus and Lotus—deploy PowerShell backdoors that facilitate persistence and remote command execution while blending into normal system activity. By combining fileless techniques with extensive post‑exploitation frameworks such as Brute Ratel and Cobalt Strike, ModernStealer can propagate laterally through complex enterprise networks. ModernStealer’s operations are not limited to credential acquisition; the actor also engages in supply‑chain compromises that threaten intellectual property theft and critical infrastructure stability. Recent analyses suggest a pattern of leveraging cloud infrastructures for command and control as well as data exfiltration, thereby increasing resilience against traditional endpoint defenses.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ModernStealer is a highly sophisticated threat actor that infiltrates organizations across a wide spectrum of industries, from government and defense to finance and healthcare. Leveraging a combination of banking trojans, downloader families, phishing campaigns, and ransomware affiliates, ModernStealer focuses primarily on financial gain while also extracting strategic intelligence. Its operations demonstrate advanced post‑exploitation techniques, fileless persistence, and supply‑chain compromise capabilities that enable widespread lateral movement.
Goals & Targeting
ModernStealer’s strategic objectives appear twofold: (1) financial exploitation through ransomware payouts and the sale of compromised credentials; and (2) intelligence gathering from defense, aerospace, and critical infrastructure sectors. The group targets a broad geographical footprint—primarily Russia, China, Iran, India, and the United States—while selectively focusing on high‑value organizations such as ministries of defense, state‑owned enterprises, educational institutions, and NGOs involved in research and development. By blending stealthy delivery mechanisms with disruptive ransomware tactics, ModernStealer seeks to maximize impact while minimizing attribution risk.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ModernStealer operates on a multi‑stage, high‑tempo campaign model. Initial infections are typically seeded through spear‑phishing emails or watering holes that deliver downloaders such as Latrodectus and Lotus. Once established, the actor deploys banking trojans to harvest credentials, which are then sold to ransomware affiliates. Subsequent stages leverage powerful post‑exploitation suites—especially Brute Ratel and Cobalt Strike—to pivot laterally, elevate privileges, and exfiltrate data via alternative protocols and cloud storage services. The group’s campaigns have exhibited a strong focus on government, defense, critical infrastructure, and high‑value intellectual property while maintaining operational overlap with other aliases like APT37 and ALPHV.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The evidence linking ModernStealer to banking trojans, downloader families, phishing campaigns and ransomware affiliate distribution is strong, drawn from multiple independent threat reports and observed IOC patterns. However, the precise attribution pathways between its numerous aliases remain partially conjectural due to limited publicly disclosed incident data. Overall confidence in the actor’s operational capabilities and strategic targets is medium‑high, while missing timeline details and definitive motive statements introduce some uncertainty.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
44
Techniques
65
Tools
7
Campaigns
40
IOCs
0
Observed Data
13
Tactics