Savvy Seahorse
Savvy Seahorse is a threat actor newly observed in CYFIRMA’s Q2 2026 finance-sector campaign dataset, where it was listed among state-sponsored APT activity targeting the finance industry. The reporting places finance organizations in 14 observed campaigns during the period, with web applications as the dominant attack surface and victim organizations spanning 32 countries, led by the United States, Japan, India, and South Korea. Savvy Seahorse was specifically described as using DNS CNAMEs and Facebook ads to lure victims to fake investment platforms. Supporting reporting on the associated scam ecosystem describes a large-scale cryptocurrency investment fraud operation that combines malvertising with pig-butchering-style social engineering, heavily targeting users in Asia, especially Japan, while expanding to other language groups. The campaigns use Facebook and Instagram ads impersonating financial experts or promoting “AI investing,” redirect victims through lure websites, and move them into legitimate messaging apps such as LINE, KakaoTalk, and WhatsApp, where one-on-one and group chats—assessed by researchers as potentially automated or AI-assisted—build trust through scripted interactions, fabricated success stories, and incentives before driving escalating deposits and eventual fraudulent transfer demands. Researchers linked more than 23,000 domains to this ecosystem and identified extensive infrastructure clustering, including RDGA-generated domains, lookalike domains, and shared website frameworks or kits. No additional aliases or sub-groups for Savvy Seahorse were provided in the source content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Banks
- Financial Services
- Insurance
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newly observed actor in the current finance-sector campaign period.
Malvertising-driven investment fraud actor previously documented using Facebook ads and DNS CNAME-based infrastructure to funnel victims to fake investment platforms.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.