Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors FusionCore

Description

The CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hacker-for- hire operation, they have a wide variety of tools and services that are being offered on their website, making it a one-stop-shop for threat actors looking to purchase cost- effective yet customizable malware. The operators have started a ransomware affiliate program that equips the attackers with the ransomware and affiliate software to manage victims. FusionCore typically provides sellers with a detailed set of instructions for any service or product being sold, enabling individuals with minimal experience to carry out complex attacks.

AI Analysis

· 1 week ago

Executive Summary

FusionCore is a European-based threat actor offering malware-as-a-service and a ransomware affiliate program, enabling less experienced attackers to conduct complex operations. Their model provides a one-stop-shop for customizable malware and hacking services, significantly lowering the barrier for cybercriminal activities.

Goals & Targeting

FusionCore's strategic objectives are primarily financial, as evidenced by their ransomware affiliate program, which incentivizes attacks for monetary gain. They target a broad range of sectors, likely prioritizing industries with accessible entry points and high-value digital assets, such as healthcare, finance, and critical infrastructure. By offering customizable malware, they cater to various threat actors, enabling them to exploit vulnerabilities across different industries and geographic regions. Their targeting profile suggests a focus on organizations with weak cybersecurity defenses, as their model empowers attackers with minimal technical expertise to execute complex operations.

Enhanced Description

The CYFIRMA research team has identified FusionCore as an emerging threat group operating from Europe, specializing in malware-as-a-service and hacker-for-hire models. This actor provides threat actors with access to a diverse portfolio of tools and services, including detailed instructions for deployment, allowing even less technically proficient individuals to execute sophisticated attacks. FusionCore's operations are facilitated through a website that acts as a marketplace for cybercriminals, offering cost-effective solutions that cater to a wide range of malicious activities. Notably, they run a ransomware affiliate program, equipping attackers with tools and software to manage victims, thereby extending their reach and operational capacity. This group's services emphasize accessibility and customization, making them a significant contributor to the proliferation of cybercrime.

Key Capabilities

  • Malware-as-a-service (MaaS) model with customizable tools
  • Ransomware affiliate program with attacker management software
  • Delivery of malicious payloads via spear-phishing and exploit kits
  • Operational support for less experienced attackers through detailed deployment instructions
  • Use of C2 infrastructure resilient to takedown attempts

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Data Exfiltration
Command and Control

ATT&CK Techniques

T1059.003 - Phishing via malicious email attachments
T1566.001 - C2 over DNS tunneling
T1192 - Exploitation of remote services
T1040 - Data exfiltration over C2 channels

Software / Tooling

Custom ransomware variants
Cobalt Strike
Mimikatz
Affiliate management software
Phishing toolkits

Campaigns & Victims

FusionCore operates with a continuous campaign tempo, leveraging their MaaS and affiliate program to sustain long-term exploitation of vulnerabilities. Their campaigns often begin with spear-phishing, followed by ransomware deployment, with a focus on rapid monetization through affiliate models. Notable operations include the proliferation of ransomware-as-a-service, enabling multiple actors to target victims simultaneously. Their infrastructure is frequently hosted on bulletproof domains, complicating attribution and takedown efforts.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 communication via DNS tunneling
  • Staging infrastructure on bulletproof hosting platforms
  • Custom malware hashes with affiliate tracking mechanisms
  • Exploit payloads targeting unpatched vulnerabilities

Recommended Actions

  • Implement advanced phishing detection and user training programs
  • Deploy network monitoring for DNS tunneling and anomalous C2 traffic
  • Block access to bulletproof hosting domains and known malicious infrastructure
  • Regularly update endpoint protections to mitigate exploit kit attacks
  • Conduct threat hunting for indicators linked to ransomware affiliate programs

Suggested Tags

APT
ransomware
malware-as-a-service
finance-sector
cybercrime

Confidence Assessment

Confidence in FusionCore's operational model and affiliations is moderate, based on CYFIRMA's reported findings. However, information gaps exist regarding their full toolset, geographic reach, and potential unattributed attacks. Further analysis of linked IOCs and campaign patterns is needed to validate specific capabilities and motives.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
malware-as-a-service
finance-sector
cybercrime

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.