ingermany is the alias of a likely Russia-based cybercriminal operator associated with botnet activity involving SmokeLoader and Fuery, and linked through shared tooling, infrastructure history, and operator registration artifacts. The operator has been tied to a custom command-and-control ecosystem that included a Flask-based panel masquerading as a legitimate business application and a separate Fuery administration panel, with multiple operational security failures enabling correlation across assets. Attribution in available reporting points to an individual using the identity German Ingrmen and places the operator in Krasnodar, Russia, although the exposed identity details are assessed as likely fabricated cover information rather than verified real-world identity. The actor’s operations center on credential and information theft. Observed SmokeLoader activity included harvesting browser credentials, stealing email client data, accessing cryptocurrency wallets, enumerating installed software and running processes, beaconing to command infrastructure, and exfiltrating stolen data. Fuery appears to be a custom Go-based Windows implant with broader post-compromise functionality, including reconnaissance, file operations, anti-analysis checks, raw-socket command-and-control, and process injection via thread context hijacking. Fuery also supported data exfiltration over SMTP by retrieving legacy OpenSSL components from its infrastructure. The same broader campaign ecosystem also delivered a cryptocurrency miner, indicating financially motivated monetization beyond pure credential theft. A notable hallmark of this actor is a shared Go 1.20.1 obfuscation framework used across Fuery and a related SmokeLoader variant. The malware embedded non-functional Raft consensus and VP8/VP9-style data structures as structural camouflage to mislead static analysis, alongside garble-style identifier obfuscation and per-build generated type names that likely served as watermarking. This uncommon development pattern strongly suggests a common developer or tightly controlled toolchain behind both malware families. The actor has demonstrated capabilities spanning initial access through malware delivery by partner botnet ecosystems, credential theft, cryptocurrency theft, reconnaissance, persistence, process injection, defense evasion, and exfiltration. Available evidence indicates the operator is distinct from CERT-UA’s UAC-0006 despite superficial overlap with SmokeLoader-related activity. The overall profile is that of a financially motivated Russian-speaking cybercriminal operator running bespoke or semi-bespoke commodity-stealer and botnet infrastructure with custom malware development and moderate operational sophistication.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator/developer linked by static analysis to Fuery and a related SmokeLoader variant through a shared Go obfuscation framework using Raft and VP8/VP9 cover types.
Operator behind a live SmokeLoader and Fuery botnet operation, using custom C2 infrastructure, a Flask-based panel disguised as "InsureFlow Pro," and shared tooling including novel Go obfuscation. The report assesses this actor as likely an independent SmokeLoader customer rather than UAC-0006.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.