Shedding Zmiy
Shedding Zmiy is a threat actor associated with the (Ex)Cobalt activity cluster and also referred to as ExCobalt in the provided reporting. The content does not provide a standalone intrusion profile for Shedding Zmiy, but it explicitly states that campaigns targeting Russian organizations showed overlaps with Shedding Zmiy/ExCobalt-linked activity. Reported overlaps included tools, infrastructure, file naming, and TTPs seen alongside other Russia-targeting groups such as MorLock, BlackJack, and Twelve. Specifically mentioned overlaps tied to Shedding Zmiy/ExCobalt-linked activity include XenAllPasswordPro, Intellpui.vbs, the CobInt backdoor, resocks, SoftPerfect Network Scanner, and dismcore.dll sideloading. The content only supports high-confidence characterization of Shedding Zmiy as a group associated with the (Ex)Cobalt cluster and linked through overlapping tooling and tradecraft to recent campaigns targeting Russian businesses and government entities.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Group associated with the (Ex)Cobalt cluster and linked here through overlap with Crypt Ghouls in DLL sideloading, CobInt, resocks, SoftPerfect Network Scanner, and VDSina-hosted C2 infrastructure.
Referenced as a separate group (aka ExCobalt) conducting similar recent campaigns targeting Russia with overlapping tools/infrastructure; no additional details provided in the content.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.