Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

Savvy Seahorse

Also known asSavvy Seahorse

Savvy Seahorse is a threat actor newly observed in CYFIRMA’s Q2 2026 finance-sector campaign dataset, where it was listed among state-sponsored APT activity targeting the finance industry. The reporting places finance organizations in 14 observed campaigns during the period, with web applications as the dominant attack surface and victim organizations spanning 32 countries, led by the United States, Japan, India, and South Korea. Savvy Seahorse was specifically described as using DNS CNAMEs and Facebook ads to lure victims to fake investment platforms. Supporting reporting on the associated scam ecosystem describes a large-scale cryptocurrency investment fraud operation that combines malvertising with pig-butchering-style social engineering, heavily targeting users in Asia, especially Japan, while expanding to other language groups. The campaigns use Facebook and Instagram ads impersonating financial experts or promoting “AI investing,” redirect victims through lure websites, and move them into legitimate messaging apps such as LINE, KakaoTalk, and WhatsApp, where one-on-one and group chats—assessed by researchers as potentially automated or AI-assisted—build trust through scripted interactions, fabricated success stories, and incentives before driving escalating deposits and eventual fraudulent transfer demands. Researchers linked more than 23,000 domains to this ecosystem and identified extensive infrastructure clustering, including RDGA-generated domains, lookalike domains, and shared website frameworks or kits. No additional aliases or sub-groups for Savvy Seahorse were provided in the source content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Banks
  • Financial Services
  • Insurance
MITRE ATT&CK

Tradecraft

1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

1 of 15 tactics1 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1190
Exploit Public-Facing Application
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping1

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.