Lurk, also known as the Lurk gang, is a Russian financially motivated cybercriminal group associated with the Lurk banking Trojan and the Angler exploit kit. It targeted Russian banks and their core banking systems, using malware-assisted intrusions to steal funds. Its banking attacks date to at least 2013, and losses attributed to the group exceeded US$45 million. Lurk used exploit-kit delivery and fileless infection techniques, reducing reliance on executable files stored on disk and complicating file-based detection. The group was linked to the development and operation of Angler, a prominent browser exploit kit. In June 2016, Russian police arrested approximately 50 suspects in connection with the Lurk investigation; Angler activity disappeared afterward. Lurk's established operations centered on financial theft rather than state-sponsored espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an active group refocusing toward banks, specifically targeting core banking systems.
Referenced only as a comparison point for tactics similar to those later used by Cobalt.
Named as one of the early groups conducting attacks on Russian banks and financial institutions.
Referenced as an example showing that groups may be investigated and taken down when they target CIS member states; linked to Angler exploit kit and targeted Russian banks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.