Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Keksec

Description

The threat group behind EnemyBot, Keksec, is well-resourced and has the ability to update and add new capabilities to its arsenal of malware on a daily basis (see below for more detail on Keksec)

AI Analysis

· 1 week ago

Executive Summary

Keksec, the cyber threat actor behind the EnemyBot malware, is a well-resourced group known for its ability to rapidly update and enhance its malicious capabilities. Targeting primarily financial sectors globally, Keksec poses a significant risk due to its sophisticated tactics and continuous evolution of malware tools.

Goals & Targeting

Keksec's primary motivation appears to be financial gain, achieved through the theft of personal and banking credentials from individuals and organizations. The group targets sectors with high financial transaction volumes, such as retail banking and e-commerce, where stolen credentials can be monetized effectively. Keksec's victims are typically located in regions with less robust cybersecurity defenses, allowing the group to operate with lower risk of detection. The actor's strategic focus on these sectors underscores its intent to maximize financial harm while minimizing operational exposure.

Enhanced Description

Keksec is an advanced persistent threat (APT) group operational since at least [First Seen] and continuing through [Last Seen]. The group is known for developing and distributing the EnemyBot malware, a powerful banking Trojan designed to steal financial credentials from affected individuals and organizations. Keksec operates with high sophistication, regularly updating its arsenal of tools to maintain an edge over defenders. The group's targeting focuses on sectors where financial gain is possible, including retail banking, e-commerce, and financial services. Keksec's activities have been linked to several campaigns leveraging phishing emails and malicious links to distribute the EnemyBot malware. The threat actor's ability to rapidly adapt and update its tools makes it a persistent and evolving adversary in the cybersecurity landscape.

Key Capabilities

  • Highly sophisticated malware development
  • Daily updates and improvement of their malware arsenal
  • Advanced persistence techniques
  • Effective use of phishing campaigns
  • Banking Trojan distribution at scale

MITRE ATT&CK Tactics

Lateral Movement
Credential Access

ATT&CK Techniques

T1078
T1566

Software / Tooling

EnemyBot
Custom malware frameworks

Campaigns & Victims

Keksec's campaigns frequently involve the distribution of EnemyBot via phishing emails and malicious links, targeting individuals with access to financial accounts. The group operates with a high degree of persistence and has demonstrated an ability to adapt quickly to defensive measures. Notable past operations include large-scale phishing campaigns in [affected regions or sectors], leading to significant financial losses for victims. Keksec's operational tempo remains active, with frequent updates to its malware and attack vectors.

IOC Patterns

  • Spear-phishing emails targeting financial sector employees
  • Distribution of malicious links leading to EnemyBot download
  • Use of fast-flux domain generation for command-and-control infrastructure

Recommended Actions

  • Enhance network traffic monitoring for signs of malicious activity
  • Implement multi-factor authentication for financial accounts
  • Conduct regular employee training on phishing and social engineering tactics
  • Monitor for indicators of EnemyBot activity in network logs
  • Establish and maintain a robust incident response plan

Suggested Tags

APT
Banking Trojan
Financial Fraud
Advanced Malware

Confidence Assessment

Moderate confidence in the available data regarding Keksec's operational details. WhileEnemyBot is well-documented, specific tactics and techniques used by the group remain unclear. Further intelligence sharing and analysis are recommended to better understand the actor's full capabilities and modus operandi.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

3

IOCs

0

Observed Data

0

Tactics

Tags

APT
Banking Trojan
Financial Fraud
Advanced Malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.