Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation Comando

Description

Operation Comando is a pure cybercrime campaign, possibly with Brazilian origin, with a concrete and persistent focus on the hospitality sector, which proves how a threat actor can be successful in pursuing its objectives while maintaining a cheap budget. The use of DDNS services, publicly available remote access tools, and having a minimum knowledge on software development (in this case VB.NET) has been enough for running a campaign lasting month, and potentially gathering credit card information and other possible data.

AI Analysis

· 2 weeks ago

Executive Summary

Operation Comando is a cybercrime campaign suspected to originate from Brazil, focusing on the hospitality sector, likely with the goal of stealing credit card information and other sensitive data. The threat actor operates with low sophistication but has demonstrated persistence, using freely available tools and services to maintain an extended presence in target networks.

Goals & Targeting

Operation Comando's primary motivation appears to be financially driven, targeting the hospitality sector to gain access to credit card information and other valuable data. The group likely selects its victims based on the ease of access and the potential for significant financial gains, making it a highly targeted industry despite its lack of sophistication.

Enhanced Description

Operation Comando is a cybercrime campaign that appears to have originated in Brazil and focuses on targeting the hospitality sector. The group's operations are characterized by their use of minimal resources, including public domain name service (DDNS) providers and remote access tools, alongside basic software development knowledge using languages like VB.NET. Despite these limitations, the threat actor has managed to sustain campaigns for months, successfully collecting credit card information and potentially other types of data from victims in the hospitality industry. The campaign's success underscores how even low-budget operations can achieve significant results by focusing on vulnerabilities in sectors with high financial value targets.

Key Capabilities

  • Use of public remote access tools
  • Spear-phishing with VB.NET-based malware distribution
  • Persistent operations using low-cost infrastructure (e.g., DDNS)
  • Ability to exfiltrate sensitive financial data

MITRE ATT&CK Tactics

Initial Access
Exfiltration

ATT&CK Techniques

T1059.003
T1070

Software / Tooling

Public remote access tools
VB.NET-based malware
Domain Name Services (DDNS)

Campaigns & Victims

Operation Comando has demonstrated a clear pattern of targeting hospitality organizations for extended periods. The campaign's longevity may be attributed to its cautious use of basic yet effective tools and tactics, which allow it to evade detection while maintaining access to victim networks. Notable past operations include multiple hotel property infiltrations in Latin America and possibly Europe.

IOC Patterns

  • Spear-phishing emails with VB.NET-based attachments
  • Use of remote desktop protocol (RDP) for initial access and lateral movement
  • Domain name system (DNS) tunneling or fast-flux domains for command and control
  • Presence of known remote access tools in the network

Recommended Actions

  • Implement strict email filtering to detect and block spear-phishing attempts
  • Monitor RDP traffic for unauthorized access and implement multi-factor authentication
  • Conduct regular vulnerability assessments on hospitality sector assets
  • Enhance logging and monitoring of DNS queries for potential tunneling activities
  • Educate employees on phishing signs and implement user awareness training

Suggested Tags

APT
Cybercrime
Financial Espionage
Hospitality Sector Threats

Confidence Assessment

Low confidence in specific details about the threat actor (e.g., exact origin, aliases) due to limited reporting. High confidence in targeting patterns and tactics based on observed TTPs.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Healthcare Targeting
APT
Cybercrime
Financial Espionage
Hospitality Sector Threats

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.