About the Malwarebox ID:
The Malwarebox ID classifies a threat actor (cluster) within the Malwarebox Initiative
APT28
Country: Russia 🇷🇺
Malwarebox ID: MB-0002
Targets: Ukraine 🇺🇦 (#1), NATO / EU
APT36
Country: Pakistan 🇵🇰
Targets: India 🇮🇳 (#1), Afghanistan 🇦🇫, Bangladesh 🇧🇩, Sri Lanka 🇱🇰
Gamaredon
Country: Russia 🇷🇺
Malwarebox ID: MB-0001
Targets: Ukraine 🇺🇦 (#1)
- Following Gamaredons Infrastructure Rotations using Kraken (1/7)
- Gamaredon: Now Downloading via Windows Updates Best Friend “BITS”
- Defending Against Gamaredon: Practical Controls That Actually Work
- Gamaredon: Same Goal, Fewer Fingerprints
- GamaWiper Explained: Gamaredon’s “New” Anti-Analysis Weapon
- Inside Gamaredon 2025: Zero-Click Espionage at Scale
- How a Russian Threat Actor Uses a Recent WinRAR Vulnerability in Their Ukraine Operations
MuddyWater
Country: Iran 🇮🇷
Malwarebox ID: MB-0004
Targets: Iraq 🇮🇶, Saudi Arabia 🇸🇦, United Arab Emirates 🇦🇪, Jordan 🇯🇴, Turkey 🇹🇷, Israel 🇮🇱, Germany 🇩🇪, United States 🇺🇸
- Observed Telegram Bot Naming Patterns in Recent MuddyWater Malware Activity
- RustyStealer: Your Compiler Is Snitching on You
- MuddyWater: When Your Build System Becomes an IOC – “Jacob”
North Korea
Country: North Korea 🇰🇵
Targets: Democracy
UAC-0184
Country: UNKNOWN
Malwarebox ID: MB-0005
Targets: Ukraine 🇺🇦 (#1)
UAC-0226
Country: UNKNOWN
Malwarebox ID: MB-0004
Targets: Ukraine 🇺🇦 (#1)
UAC-0244/UAC-0247
Country: UNKNOWN
Malwarebox ID: MB-0006
Targets: Ukraine 🇺🇦 (#1)
Unknown
Country: UNKNOWN
Targets: UNKNOWN
All
- UAC-0244 / UAC-0247: Malware Targeting FPV drone operators
- UAC-0184: From HTA to a Signed Network Stack
- 3.000 “Stealer” Samples, One Misconfigured Apache Server
- Obfuscation Without Effort: Breaking a UAC-0226 GIFTEDCROOK Stealer
- Following Gamaredons Infrastructure Rotations using Kraken (1/7)
- Observed Telegram Bot Naming Patterns in Recent MuddyWater Malware Activity
- APT28: Geofencing as a Targeting Signal (CVE-2026-21509 Campaign)
- Why Is a North Korean Mail Server Using a .cc Domain? – Threat Intelligence Beyond Malware
- RustyStealer: Your Compiler Is Snitching on You
- Gamaredon: Now Downloading via Windows Updates Best Friend “BITS”
- MuddyWater: When Your Build System Becomes an IOC – “Jacob”
- Defending Against Gamaredon: Practical Controls That Actually Work
- Gamaredon: Same Goal, Fewer Fingerprints
- GamaWiper Explained: Gamaredon’s “New” Anti-Analysis Weapon
- Inside Gamaredon 2025: Zero-Click Espionage at Scale
- How a Russian Threat Actor Uses a Recent WinRAR Vulnerability in Their Ukraine Operations
- APT36 – “Abaris” Deobfuscating VB Dropper
- APT44 – Sandworm Team
- APT1