DDGroup is a long-running cybercrime threat cluster active since at least late 2019 and associated with phishing-led malware delivery operations using commodity remote access trojans and loaders. The group has been linked to campaigns involving XWorm, AsyncRAT, Quasar RAT, BitRAT, Remcos, NetWire, Warzone RAT/AveMaria RAT, and ModiLoader/DBatLoader. Its operations have featured social-engineering lures such as invoice-themed documents and abuse of Windows search-ms behavior combined with WebDAV to present attacker-hosted content through Windows Explorer and induce victim execution. DDGroup has shown repeated reliance on dynamic DNS infrastructure and commodity or open-source tooling to support delivery and post-compromise activity. Reported tooling associated with the cluster includes the open-source dufs file-sharing server for WebDAV-style hosting and a Rust-based crypter or packer assessed to be derived from Freeze.rs. The crypter has been linked to process injection into legitimate processes and suspended-process execution techniques to launch protected payloads while hindering analysis and detection. The actor appears to favor scalable initial-access and malware distribution tradecraft rather than bespoke implants. Observed behavior includes phishing, malicious attachments or links, WebDAV-hosted payload staging, defense evasion through packing or crypter use, and post-exploitation via commodity RAT capabilities. Across the malware families associated with DDGroup campaigns, supported capabilities include credential theft, keylogging, exfiltration, persistence, and broader remote access functions. DDGroup has also been noted as an early adopter of OneNote-based malware delivery in 2023 and an early adopter of the search-ms/WebDAV technique the same year. DDGroup is best characterized as a financially motivated cybercrime actor focused on malware delivery and access operations rather than a nation-state espionage group. No high-confidence country of origin or consistently targeted country and sector attribution is currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a reference title as a long-time threat actor linked with multiple commodity RATs and loaders.
A long-running cybercrime threat actor tracked by the author as DDGroup, active since at least 2019, using phishing-based initial access and rapidly adopting new delivery vectors such as search-ms/WebDAV and OneNote lures. The group relies heavily on dynamic DNS infrastructure, open-source tooling, and commodity RATs/loaders for malware delivery and C2.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.