The CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hacker-for- hire operation, they have a wide variety of tools and services that are being offered on their website, making it a one-stop-shop for threat actors looking to purchase cost- effective yet customizable malware. The operators have started a ransomware affiliate program that equips the attackers with the ransomware and affiliate software to manage victims. FusionCore typically provides sellers with a detailed set of instructions for any service or product being sold, enabling individuals with minimal experience to carry out complex attacks.
Executive Summary
FusionCore is a European-based threat actor offering malware-as-a-service and a ransomware affiliate program, enabling less experienced attackers to conduct complex operations. Their model provides a one-stop-shop for customizable malware and hacking services, significantly lowering the barrier for cybercriminal activities.
Goals & Targeting
FusionCore's strategic objectives are primarily financial, as evidenced by their ransomware affiliate program, which incentivizes attacks for monetary gain. They target a broad range of sectors, likely prioritizing industries with accessible entry points and high-value digital assets, such as healthcare, finance, and critical infrastructure. By offering customizable malware, they cater to various threat actors, enabling them to exploit vulnerabilities across different industries and geographic regions. Their targeting profile suggests a focus on organizations with weak cybersecurity defenses, as their model empowers attackers with minimal technical expertise to execute complex operations.
Enhanced Description
The CYFIRMA research team has identified FusionCore as an emerging threat group operating from Europe, specializing in malware-as-a-service and hacker-for-hire models. This actor provides threat actors with access to a diverse portfolio of tools and services, including detailed instructions for deployment, allowing even less technically proficient individuals to execute sophisticated attacks. FusionCore's operations are facilitated through a website that acts as a marketplace for cybercriminals, offering cost-effective solutions that cater to a wide range of malicious activities. Notably, they run a ransomware affiliate program, equipping attackers with tools and software to manage victims, thereby extending their reach and operational capacity. This group's services emphasize accessibility and customization, making them a significant contributor to the proliferation of cybercrime.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
FusionCore operates with a continuous campaign tempo, leveraging their MaaS and affiliate program to sustain long-term exploitation of vulnerabilities. Their campaigns often begin with spear-phishing, followed by ransomware deployment, with a focus on rapid monetization through affiliate models. Notable operations include the proliferation of ransomware-as-a-service, enabling multiple actors to target victims simultaneously. Their infrastructure is frequently hosted on bulletproof domains, complicating attribution and takedown efforts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in FusionCore's operational model and affiliations is moderate, based on CYFIRMA's reported findings. However, information gaps exist regarding their full toolset, geographic reach, and potential unattributed attacks. Further analysis of linked IOCs and campaign patterns is needed to validate specific capabilities and motives.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics