Lurk was a Russian cybercriminal group centered on banking fraud and intrusions into financial institutions, particularly Russian banks and core banking environments. The group is associated with the Lurk banking trojan and has been linked to the Angler exploit kit ecosystem. Reporting ties Lurk to early fileless infection techniques and exploit-kit-driven delivery, including attacks that executed payloads in memory rather than relying solely on conventional files on disk. The group was credited with stealing more than $45 million from financial institutions and was disrupted after Russian law enforcement arrested numerous suspects in 2016. Lurk is consistently described as a financially motivated actor focused on the financial sector. Its operations targeted banks’ internal systems rather than broad consumer fraud alone, placing it among the early wave of Russian-speaking groups that conducted targeted attacks on banks alongside actors such as Anunak, Buhtrap, Corkow, and later Cobalt. Lurk has specifically been associated with attacks on core banking systems and with malware used in Russia. The group’s known tradecraft includes exploit-kit-enabled initial access, phishing as a common infection vector in the broader banking intrusion ecosystem it operated within, and fileless or memory-resident execution. Lurk has also been linked to use of legitimate administrative tools and stealthier post-compromise methods characteristic of targeted financial intrusions. Historical reporting connects early Angler-related activity to probable Lurk payload delivery, reinforcing the group’s role in sophisticated exploit-driven banking attacks. Aliases include Lurk Gang and related investigation-context variants. High-confidence public reporting supports Lurk as a Russian-origin cybercrime group rather than a state-sponsored actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an active group refocusing toward banks, specifically targeting core banking systems.
Referenced only as a comparison point for tactics similar to those later used by Cobalt.
Named as one of the early groups conducting attacks on Russian banks and financial institutions.
Referenced as an example showing that groups may be investigated and taken down when they target CIS member states; linked to Angler exploit kit and targeted Russian banks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.