Haskers Gang is a crimeware threat actor active since at least 2020 and associated with the creation, promotion, and distribution of the .NET-based infostealer ZingoStealer. The group operates primarily in Russian-speaking cybercrime communities and is assessed to be based in Eastern Europe, with strong indications of Russian-language operations. Haskers Gang used Telegram and Discord as core operational platforms for malware distribution, update announcements, coordination, and delivery of stolen-data logs to users of its tooling. The group’s best-documented activity centers on ZingoStealer, which it released for free to its community and later attempted to sell. ZingoStealer targets consumer systems, especially Russian-speaking home users, and is commonly distributed through social-engineering lures themed around game cheats, cracks, key generators, pirated software, and free software offers. The malware steals browser data, saved credentials, cookies, system information, collaboration-platform tokens, cryptocurrency wallet extensions, wallet files, screenshots, and user desktop files. It stages and archives collected data before exfiltration. Haskers Gang also used ZingoStealer as a loader for secondary payloads, notably RedLine Stealer and an XMRig-based miner referred to as ZingoMiner, expanding monetization beyond simple credential and wallet theft. Observed follow-on activity included downloading and executing additional malware, establishing persistence, injecting mining components into legitimate processes, and adding antivirus exclusions to support mining operations. The group additionally offered an ExoCrypt crypter service to help users evade antivirus detection. The actor’s operational pattern is consistent with financially motivated cybercrime focused on credential theft, cryptocurrency theft, and broader monetization of infected consumer endpoints. Available evidence indicates a preference for avoiding victims in CIS countries, a behavior commonly associated with Russian-speaking criminal operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group behind the creation, free distribution, and attempted sale of the ZingoStealer information-stealing malware. The malware is promoted in Russian-speaking channels, infects victims via software cracks and game cheats, steals browser and cryptocurrency wallet data, can load second-stage payloads, and can deploy XMRig for Monero mining.
Crimeware group developing and distributing ZingoStealer, coordinating via Telegram and Discord, stealing credentials and cryptocurrency wallet data, delivering secondary payloads including RedLine Stealer and XMRig, and monetizing infections through log sales and cryptomining.
Crimeware group active since at least January 2020 that develops and distributes ZingoStealer, coordinates via Telegram and Discord, steals credentials and cryptocurrency wallet data, delivers additional payloads including RedLine Stealer and XMRig, and monetizes infections through log access services and cryptomining.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.