GS7 is a financially motivated cybercriminal threat actor associated with large-scale phishing and brand-impersonation operations, most notably Operation DoppelBrand. The actor has targeted Fortune 500 companies and their customers, with a strong emphasis on major financial institutions and additional activity against technology, healthcare, telecommunications, insurance, and investment-sector organizations. Reported victimology shows a primary focus on English-speaking markets, especially the United States, while also indicating broader global targeting and activity in Western Europe. GS7’s tradecraft centers on high-fidelity credential-harvesting portals that closely mimic legitimate enterprise and consumer login pages. The actor has operated extensive and frequently rotated phishing infrastructure, including large volumes of lookalike domains, automated registration patterns, and traffic proxying or CDN fronting to hinder attribution and takedown. Collected victim data has included usernames, passwords, and contextual telemetry such as device, browser, and geolocation information, with exfiltration routed through attacker-controlled Telegram bots and channels. Beyond phishing, GS7 has been linked to post-compromise deployment of legitimate remote monitoring and management tools to establish persistent remote access on victim systems. Reported tooling and delivery methods indicate use of scripted loaders and installer-based deployment flows, including privilege-elevation attempts and cleanup steps intended to reduce forensic visibility. This combination of credential theft, remote access enablement, and infrastructure rotation reflects a mature initial-access operation rather than a simple phishing crew. GS7 is widely assessed as functioning as an initial access broker, monetizing harvested credentials and compromised access through underground markets and Telegram-based channels, and potentially enabling follow-on intrusion activity by other criminal actors, including ransomware affiliates. Reporting also links the actor to Brazilian cybercrime forums and credential-trading ecosystems, but no high-confidence country of origin has been established. Known aliases in the available reporting are limited to GS7 and GS.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting credential-harvesting phishing campaigns against major enterprises using sophisticated phishing kits, highly accurate brand impersonation, and automated batch domain registration.
Financially motivated phishing/credential-harvesting actor using brand impersonation, lookalike domains, and Telegram bots; may function as an initial access broker and/or deploy RMM tooling for persistence/remote access.
Financially motivated initial access broker running large-scale phishing with cloned portals to steal credentials, then monetizing access by selling credentials; also drives victims to install legitimate RMM tools for persistent remote access.
Financially motivated phishing and initial-access-broker activity targeting major brands: clones banking/tech portals to steal credentials, then pushes victims to install legitimate remote access/RMM tools for persistence; monetizes by selling credentials on Telegram/underground markets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.