Operation DupeHike is a threat activity cluster associated with multi-stage spearphishing campaigns targeting Russian organizations. The operation uses Russian-language business-themed lures delivered in compressed archives containing malicious shortcut files disguised with double extensions. Rather than relying on software exploits, the intrusion chain abuses native Windows functionality including PowerShell, VBScript, registry modification, and file-association hijacking. Public cloud services are used for payload staging, while Telegram is used extensively for operator notification, command-and-control, and exfiltration. Observed tradecraft includes opening decoy documents to distract victims, delayed execution between stages, repeated attempts to obtain elevated privileges through UAC prompts, and deliberate weakening of endpoint protections by adding Microsoft Defender exclusions and disabling Defender through registration of a fake antivirus product. The operation has also deployed surveillance components that capture screenshots at regular intervals and exfiltrate them, alongside remote-access tooling used for data theft and follow-on payload delivery. Persistence has been maintained through registry changes and file-association abuse, and administrative or diagnostic tools have been disabled to hinder response. The activity has been linked to deployment of Amnesia RAT for remote access and theft of data, credentials, and cryptocurrency-related information, including targeting Chromium-based browser data and desktop applications such as messaging and gaming clients. Ransomware from the Hakuna Matata family has also been used for file encryption, with additional behavior including clipboard hijacking for cryptocurrency theft and possible screen-locking functionality. The operation therefore combines espionage-oriented surveillance and collection with financially motivated ransomware and crypto-theft behavior. Related activity has been linked to Paper Werewolf, also known as GOFFEE, and the cluster is tracked as UNG0902.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.