Aggah is a financially motivated crimeware threat actor associated with recurring malspam-led malware delivery campaigns that use commodity remote access trojans and information stealers. Activity linked to Aggah has been correlated across campaigns delivering Agent Tesla, Revenge RAT, NanoCore RAT, njRAT, AsyncRAT, AZORult, AveMariaRAT, Rhadamanthys, and zgRAT. The actor is particularly noted for modular, multi-stage infection chains built around malicious Office documents, especially PowerPoint add-in abuse, VBA macros, script-based loaders, and living-off-the-land execution through tools such as mshta and PowerShell. A characteristic Aggah tradecraft pattern is the use of phishing lures themed around routine business communications such as purchase orders, payment details, pricing, negotiations, specifications, lease agreements, and tax-related matters. Campaigns have used renamed PowerPoint add-in files that trigger application errors and execute Auto_Close macros, macro-enabled Office documents that retrieve subsequent stages, and password-protected archives containing scripts. Aggah has repeatedly hosted staged payloads and scripts on public paste services, including Pastebin and paste.ee, and has obscured retrieval URLs through shortening services and string obfuscation. Observed infection chains include VBA launching remotely hosted VBScript or HTA content, PowerShell downloaders, persistence via Run and RunOnce mechanisms, Startup-folder abuse, and scheduled tasks. Later stages have included reflective loading of .NET components and process hollowing or other process injection to launch final payloads inside benign processes. Campaigns attributed or aligned to Aggah have also shown defense-evasion behavior such as obfuscation, delayed execution, and in some related clusters, attempts to weaken or bypass endpoint protections. Aggah operations have targeted organizations across multiple regions and sectors. Documented targeting includes businesses in Europe, manufacturing-heavy victim sets, travel and hospitality organizations in Latin America in overlapping activity, and users in Asia including South Korea and Indonesia. The actor has used spoofed business identities from several countries to improve phishing credibility. One notable 2020 variant added cryptocurrency theft through clipboard hijacking, replacing copied wallet addresses to divert payments. Aggah is best understood as a crimeware operator or campaign cluster rather than a nation-state actor. Reporting has also identified technical overlap between Aggah-linked activity and other campaigns using shared crypters or common malware-building ecosystems, indicating that some similarities may reflect shared tooling rather than a single unified operator in every case.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
105 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware delivery campaign using malicious Microsoft Office PowerPoint attachments and macros to deliver AZORult, NanoCore RAT, and previously Revenge RAT. The campaign targeted users in South Korea and Indonesia and used multi-stage loaders, Pastebin-hosted payloads, scheduled tasks, registry persistence, PowerShell, and process hollowing.
Externally tracked threat actor associated with distributing Rhadamanthys as part of broader crimeware activity.
Associated with a tax-themed malware delivery campaign impersonating a tax software solutions organization. The campaign used a JavaScript downloader hosted on Microsoft Azure, which invoked PowerShell to execute Rhadamanthys, followed by download and execution of zgRAT.
Historically observed using NanoCore RAT in campaigns referenced by the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.