DeathStalker is a Russian-speaking mercenary threat actor and suspected hack-for-hire or information-broker group active since at least 2015 and publicly disclosed in 2020. The group was initially named Deceptikons before being renamed DeathStalker. Its operations are associated primarily with corporate espionage rather than traditional state-directed intelligence collection, with a sustained focus on stealing business and financial information from private-sector targets. DeathStalker has consistently targeted law firms, financial institutions, fintech companies, foreign exchange brokers, cryptocurrency trading companies, and travel-related organizations, especially in Europe and the Middle East. Reported victim geography includes the United Kingdom, Egypt, Saudi Arabia, the United Arab Emirates, Georgia, Israel, and Jordan, with later activity also affecting organizations in Cyprus, Germany, Kuwait, Malta, Bulgaria, and Russia. The actor is known for highly targeted spear-phishing campaigns that commonly use malicious shortcut files, archive attachments, and later Office document remote-template chains to deliver custom malware. Its tooling includes the PowerSing and PowerPepper families, Janicab variants, and the VileRAT toolchain, including VileDropper and VileLoader. VileRAT is a Python remote access trojan associated with DeathStalker and used in campaigns against foreign exchange and cryptocurrency firms from 2020 onward. Janicab activity attributed to the group targeted legal entities and financial organizations in the Middle East and Europe and used multi-stage VBScript and Python-based components. DeathStalker repeatedly uses dead-drop resolvers on public platforms to conceal command-and-control endpoints and has shown strong tradecraft continuity across malware families. Observed capabilities include persistence through startup items and scheduled tasks, remote command execution, keylogging, screenshot capture, proxying, reverse tunneling, downloading additional tools, host reconnaissance including security-product enumeration, and anti-analysis or anti-virtualization checks. The group has also used custom loaders, obfuscated scripts, in-memory execution, and staged payload delivery to evade detection. Reporting has characterized the actor as operationally clever and persistent rather than reliant on zero-day exploitation. DeathStalker is widely assessed as part of the broader mercenary APT ecosystem: a private-sector offensive actor conducting intrusions on behalf of clients or for resale of stolen intelligence. No high-confidence public attribution to a specific government or real-world organization is established in the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
466 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A threat actor reportedly associated with unique use of VileRAT and previously described as highly targeted to financial tech.
Hack-for-hire or mercenary-style intrusion actor conducting long-running espionage and intelligence-gathering campaigns against foreign exchange and cryptocurrency trading companies using the VileRAT infection chain.
Russian-speaking mercenary APT focused on corporate espionage, primarily targeting law firms and financial institutions to gather sensitive business information.
Long-running intrusion set (traceable back to ~2015) targeting primarily legal and financial organizations (and possibly travel) in the Middle East and Europe; uses Janicab variants and dead-drop resolver infrastructure on public web services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.