Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors mogilevich

Description

Mogilevich appeared in February 2024, rapidly claiming high-profile breaches of Epic Games, DJI, Shein, and Kick.com, but was quickly exposed as a fraud — the group's operator admitted they were "professional fraudsters" who sold fake breach data and access to a non-existent RaaS panel. Known victims: 8

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Mogilevich emerged in February 2024 as a threat actor claiming high-profile breaches of major companies. However, the group was quickly exposed as fraudsters, with their operator admitting to selling fake breach data and access to a non-existent RaaS panel. The threat actor has targeted sectors including gaming, technology, and e-commerce, seeking financial gain through fraudulent activities.

Goals & Targeting

Mogilevich primarily targets sectors with significant public exposure and potential for financial leverage, such as gaming (Epic Games), technology (DJI), e-commerce (Shein), and online marketplaces (Kick.com). The threat actor's strategic focus appears to be on creating panic and distrust in organizations by falsely claiming breaches. Their goal is to monetize through the sale of fake breach data or fraudulent RaaS access, rather than deploying actual ransomware or conducting damaging attacks.

Enhanced Description

Mogilevich, identified as a criminal threat actor, first appeared in February 2024 with ambitious claims of compromising high-profile companies such as Epic Games, DJI, Shein, and Kick.com. These claims迅速引起了 attention, but the group was later revealed to be operating fraudulent schemes. The operator of this threat actor admitted that Mogilevich is a 'professional fraudster,' engaging in scams rather than legitimate cyberattacks. The group's strategy involved selling fake breach data and offering access to a non-existent Ransomware as a Service (RaaS) panel. This revelation highlights the group's focus on financial gain through deceptive methods rather than actual technical exploitation. The emergence of Mogilevich underscores the increasing sophistication of criminal actors in leveraging reputational damage and fear tactics to extract monetary gains, even if the underlying claims are false.

Key Capabilities

  • Social engineering
  • Phishing (via email or messaging platforms)
  • Pretexting
  • Fraudulent breach claims
  • Fake Ransomware as a Service (RaaS) offerings

Software / Tooling

Custom social engineering tools
Phishing kits

Campaigns & Victims

Mogilevich's campaign was short-lived, with activity observed between February and March 2024. The group targeted high-profile organizations across multiple industries, leveraging the credibility of these companies to maximize their fraudulent efforts. The quick exposure of their operations suggests a lack of operational discipline and genuine technical capability, focusing instead on deceptive marketing tactics.

IOC Patterns

  • Spear-phishing emails claiming data breaches
  • Fraudulent offers for RaaS panel access
  • Non-functional breach reporting websites
  • Loyalty to criminal fraud schemes over actual exploitation

Recommended Actions

  • Educate employees about phishing and social engineering attempts
  • Monitor for unusual network activity related to data breaches
  • Verify any claims of breaches or unauthorized access with internal security teams
  • Engage ethical hacking exercises to test organizational resilience against fraud

Suggested Tags

APT
ransomware
fraud
criminal
e-commerce
technology
gaming sector

Confidence Assessment

Low confidence in the available data due to the lack of technical details, such as specific tools or techniques used. The threat actor's short operational window and fraudulent claims make it difficult to assess true capabilities. However, their focus on financial gain through deception provides sufficient context for basic defensive measures.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
ransomware
fraud
criminal
e-commerce
technology
gaming sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 20, 2024
Last Seen
Mar 1, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.