🇷🇺

COOKIE SPIDER

APT Group 3 zero-day CVEs

Also Known As

No alias recorded

Target Countries 21

Countries highlighted in red

Brazil Canada China Colombia France United Kingdom Georgia India Italy Japan Kyrgyzstan Sri Lanka Mexico Nauru Romania Tajikistan Turkmenistan Turkey United States Uzbekistan Vietnam

Sectors Targeted

National Security and International Affairs 928 Information Technology Telecommunications NAICS:31 31 Computer and Electronic Product Manufacturing 334 Cybersecurity Public Administration 92 Retail NAICS:44 44 Couriers and Express Delivery Services 492110 Airline Energy Healthcare Industrial Insurance Utilities 22 Multiple sectors Financial Services Other Services (except Public Administration) 81 Commodity Contracts Intermediation 523160 Finance Entertainment Insurance Carriers and Related Activities 524 Information 51 Diplomatic Transportation Telecom Software/IT Financial Government Automobile Dealers 4411 Logistics Internet Publishing and Broadcasting and Web Search Portals 51913 Couriers and Express Delivery Services 4921 IT Managed Service Providers Health Care and Social Assistance 62 Multiple utilities) Social Media commercial and critical infrastructure sectors Defense Personal Multiple sectors (finance Individuals Various (retail Advertising Critical Infrastructure Computer Systems Design and Related Services 5415 Consumer Services media Technology etc.) Business Computer Systems Design Services 541512 financial technology Finance and Insurance 52 Telecommunications 517 Automotive Manufacturing entertainment Software Publishers 5112 Data Security NAICS:48 48

Details

Origin 🇷🇺 RU
Last Updated 02 Sep 2025

MITRE ATT&CK 25

T1005 - Data from Local System T1027 - Obfuscated Files or Information T1056.001 - Keylogging T1056.002 - GUI Input Capture T1059 - Command and Scripting Interpreter T1059.004 - Unix Shell T1074.001 - Local Data Staging T1082 - System Information Discovery T1083 - File and Directory Discovery T1087 - Account Discovery T1105 - Ingress Tool Transfer T1113 - Screen Capture T1114 - Email Collection T1115 - Clipboard Data T1132.001 - Standard Encoding T1189 - Driveby Compromise T1195 - Supply Chain Compromise T1204 - User Execution T1497 - Virtualization Sandbox Evasion T1552.001 - Credentials In Files T1555 - Credentials from Password Stores T1555.001 - Keychain T1566 - Phishing T1571 - Non-Standard Port T1583 - Acquire Infrastructure