STAC4365
STAC4365 is a threat cluster tracked by Sophos as a ransomware affiliate of the Qilin ransomware-as-a-service operation. Sophos assessed with high confidence that STAC4365 was responsible for a January 2025 incident affecting a managed service provider and multiple downstream customer environments. The group has been linked by Sophos to phishing activity dating back to November 2022. According to the provided content, STAC4365 relies on adversary-in-the-middle phishing to steal credentials and bypass MFA, using the evilginx framework, spoofed ScreenConnect domains, and Amazon SES tracking redirects. In the cited intrusion, the actor impersonated a ScreenConnect authentication alert, redirected the victim through awstrack[.]me infrastructure to a fake ScreenConnect domain, proxied the legitimate login flow, captured credentials and a time-based one-time password, and then authenticated to the legitimate ScreenConnect Cloud portal using a compromised super administrator account. After obtaining access, STAC4365 deployed an attacker-managed ScreenConnect instance named ru.msi across multiple customer environments. The actor then conducted network enumeration, user discovery, credential resets, lateral movement, data collection, and exfiltration before deploying Qilin ransomware. Observed tooling and techniques included use of legitimate tools and Windows utilities such as PsExec, NetExec, WinRM, and ScreenConnect for remote command execution and credential access; use of veeam.exe associated with exploitation of CVE-2023-27532 to obtain unencrypted credentials from Veeam Cloud Backup; compression of data with WinRAR; exfiltration of archives to easyupload.io using Chrome Incognito mode; and targeting of backups and modification of boot options to force Safe Mode with networking prior to ransomware deployment. The content identifies STAC4365 specifically as an affiliate group of Qilin. Qilin is also referred to in the content as Agenda, and is described as a ransomware-as-a-service operation active since 2022.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
Tradecraft
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster associated with phishing infrastructure spoofing ScreenConnect since late 2022, using evilginx and tracking-link gating to harvest credentials and MFA tokens and enable downstream ransomware deployment.
Qilin affiliate group reported to use adversary-in-the-middle phishing to steal credentials (MFA bypass via session capture implied).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.