BlackToad is a cybercriminal operational cluster tracked by JUMPSEC for a Remcos RAT phishing campaign targeting corporate users with Thai-language financial lures. Its emails impersonate business payment-slip communications and direct recipients to malicious downloads hosted on a legitimate file-sharing service. The downloaded payloads use deceptive double extensions to masquerade as documents while functioning as WinRAR self-extracting executables. The infection chain launches an obfuscated Visual Basic script followed by a renamed legitimate AutoIt interpreter executing a custom crypter. The script temporarily disables network connectivity before launching the AutoIt stage and restores connectivity afterward. The crypter employs extensive comment padding, antivirus and sandbox checks, and substitution-based payload encoding. It establishes persistence through a per-user Windows startup registry entry and deploys Remcos Pro. The Remcos configuration is RC4-encrypted, and command-and-control communications use multiple dynamic DNS providers for redundancy. Multiple payloads sharing infrastructure and payment-slip themes establish that BlackToad operates a multi-target campaign rather than a single isolated intrusion. Its infrastructure has used Nigerian mobile-carrier networks and commercial hosting, but infrastructure location does not establish the operators’ country of origin. No confirmed aliases or subordinate groups are established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a Remcos RAT phishing campaign using Thai-language financial lures, disguised archive/document executables, extension masquerading, temporary network blackout evasion, and redundant dynamic-DNS C2 infrastructure targeting corporate networks.
A newly tracked, likely Nigeria-based activity cluster delivering Remcos through payment-themed phishing, self-extracting archives, an obfuscated VBS loader, and a custom AutoIt crypter. Its distinctive delivery technique temporarily releases the victim's network connection during payload execution to interfere with cloud-based security checks. Infrastructure overlaps suggest a possible continuation of, or affiliation with, BoredFluff, but the relationship is not confirmed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.