Deathstalker
DeathStalker is a cyber-mercenary threat actor. The provided content links the group to intrusions targeting legal entities in the Middle East and to use of the Janicab malware family. The content also describes updated intrusions possibly related to DeathStalker that used an updated DarkMe VB6 OCX/DLL implant together with stealthier TTPs. The only alias directly provided in the content is deathstalker.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- legal
- finance
- travel
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyber-mercenary activity (possible) using updated DarkMe implant; delivery shifted from Skype to Telegram channels (e-trading/fintech themed) with improved OPSEC and cleanup.
Long-running intrusion set (traceable back to ~2015) targeting primarily legal and financial organizations (and possibly travel) in the Middle East and Europe; uses Janicab variants and dead-drop resolver infrastructure on public web services.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.