Leda Elacoate is a threat actor associated with a 2026 software trojanization and supply-chain-style malware distribution campaign that targeted users seeking cryptocurrency-related software and later users of X-VPN. The actor prepared and distributed multiple trojanized installers for widely used applications, initially focusing on cryptocurrency trading and wallet software before pivoting to a trojanized VPN installer to broaden victim reach. The operation relied on DLL sideloading using a malicious CRYPTBASE.dll placed alongside legitimate application components. Across observed packages, the delivery chain used a consistent multi-stage in-memory unpacking process to launch STX RAT while minimizing forensic artifacts on disk. The actor’s malware deployment allowed the legitimate application to continue functioning, reducing user suspicion while the malicious payload executed in the background. STX RAT provided both remote access trojan and infostealer functionality. Observed capabilities included theft of saved browser credentials, session tokens, and clipboard data, as well as persistent remote control of infected systems. Communications were conducted over HTTPS, consistent with efforts to blend command-and-control traffic with normal network activity. The campaign’s repeated packaging pattern and configuration choices were assessed as consistent with use of a builder-based toolkit rather than wholly bespoke malware development. Known activity indicates deliberate staging and iterative expansion over roughly a month, with new trojanized packages added over time and earlier lures replaced as the campaign evolved. The actor’s tradecraft demonstrates initial access through malicious software distribution, defense evasion through in-memory execution and masquerading as legitimate software, credential and session theft, and post-compromise remote access. No high-confidence attribution to a nation-state or specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.