Alibaba2044 is a threat actor associated with a malicious spam campaign observed in December 2022 that targeted users in Italy and delivered the PureLogs information stealer. The operation relied on email-based initial access using a password-protected archive, followed by staged execution of a loader that decrypted an embedded payload in memory and loaded the final stealer via .NET reflection. This tradecraft indicates use of user execution, in-memory payload decryption, and defense-evasion techniques intended to hinder straightforward static analysis. The actor used PureLogs, a commercial .NET infostealer, to collect sensitive data from infected systems. PureLogs is designed to steal browser-stored information, including passwords, cookies, browsing history, autofill data, and extension-related data, and to harvest credentials or tokens from multiple desktop applications and VPN clients. It also targets cryptocurrency wallet data. The observed intrusion chain included delivery through spam, execution of a disguised archive stage, deployment of a .NET loader, runtime decryption of the payload, and automated collection and exfiltration of victim data. At high confidence, Alibaba2044 is best characterized as a financially motivated cybercriminal actor conducting credential and information theft through commodity malware. No high-confidence evidence directly supports attribution to a nation state or to a broader named intrusion cluster beyond the single alias Alibaba2044.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.