Mogilevich appeared in February 2024, rapidly claiming high-profile breaches of Epic Games, DJI, Shein, and Kick.com, but was quickly exposed as a fraud — the group's operator admitted they were "professional fraudsters" who sold fake breach data and access to a non-existent RaaS panel. Known victims: 8
Objectives
Executive Summary
Mogilevich emerged in February 2024 as a threat actor claiming high-profile breaches of major companies. However, the group was quickly exposed as fraudsters, with their operator admitting to selling fake breach data and access to a non-existent RaaS panel. The threat actor has targeted sectors including gaming, technology, and e-commerce, seeking financial gain through fraudulent activities.
Goals & Targeting
Mogilevich primarily targets sectors with significant public exposure and potential for financial leverage, such as gaming (Epic Games), technology (DJI), e-commerce (Shein), and online marketplaces (Kick.com). The threat actor's strategic focus appears to be on creating panic and distrust in organizations by falsely claiming breaches. Their goal is to monetize through the sale of fake breach data or fraudulent RaaS access, rather than deploying actual ransomware or conducting damaging attacks.
Enhanced Description
Mogilevich, identified as a criminal threat actor, first appeared in February 2024 with ambitious claims of compromising high-profile companies such as Epic Games, DJI, Shein, and Kick.com. These claims迅速引起了 attention, but the group was later revealed to be operating fraudulent schemes. The operator of this threat actor admitted that Mogilevich is a 'professional fraudster,' engaging in scams rather than legitimate cyberattacks. The group's strategy involved selling fake breach data and offering access to a non-existent Ransomware as a Service (RaaS) panel. This revelation highlights the group's focus on financial gain through deceptive methods rather than actual technical exploitation. The emergence of Mogilevich underscores the increasing sophistication of criminal actors in leveraging reputational damage and fear tactics to extract monetary gains, even if the underlying claims are false.
Key Capabilities
Software / Tooling
Campaigns & Victims
Mogilevich's campaign was short-lived, with activity observed between February and March 2024. The group targeted high-profile organizations across multiple industries, leveraging the credibility of these companies to maximize their fraudulent efforts. The quick exposure of their operations suggests a lack of operational discipline and genuine technical capability, focusing instead on deceptive marketing tactics.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in the available data due to the lack of technical details, such as specific tools or techniques used. The threat actor's short operational window and fraudulent claims make it difficult to assess true capabilities. However, their focus on financial gain through deception provides sufficient context for basic defensive measures.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics