ingermany
ingermany is the alias of a suspected single operator linked to a live botnet operation involving SmokeLoader and Fuery. The reporting ties this operator to a shared Go 1.20.1 malware development toolchain and a distinctive obfuscation framework that disguises malware structures with Raft consensus protocol type names such as AppendEntries, VoteRequest, and LogEntry; related analysis also notes VP8/VP9-themed cover structures in Fuery. Static analysis linked a Fuery sample and a related SmokeLoader variant to the same developer, and one report attributes the operator to the handle ingermany, identifying the persona as "German Ingrmen" in Krasnodar, Russia based on exposed WHOIS and SOA data; the same reporting assesses that identity as likely fabricated but internally consistent. The actor operated SmokeLoader infrastructure using domains including coox.live, baxe.pics, and ropea.top. SmokeLoader used split command-and-control functions across non-standard high ports, including TCP beaconing to coox.live:28313 and HTTP multipart/form-data exfiltration to baxe.pics:48261. Sandbox analysis of the linked sample showed credential theft from browsers, theft of email client data, cryptocurrency wallet access, and software and process enumeration. Researchers identified a live Flask-based C2 panel on coox.live masquerading as an insurance SaaS platform called "InsureFlow Pro," with an exposed unauthenticated /admin dashboard and /healthz endpoint, along with multiple OPSEC and implementation weaknesses. Certificate and hosting history linked botmind-sa.com, baxe.pics, coox.live, ropea.top, forestoaker.com, and oahgsfwklg.top within the operator’s infrastructure history. The same operator was also linked to Fuery infrastructure centered on laf.oahgsfwklg.top at 178.16.54.79, using an nginx/PHP/Laravel-based panel named "Monkey." Fuery used POST requests to single-letter endpoints such as /t, /s, /c, /f, and /v, and downloaded outdated OpenSSL DLLs to enable SMTP exfiltration via Gmail over port 465. Separate static analysis describes Fuery as a garble-obfuscated Go implant delivered by the Amadey botnet in campaign fbf543 and masquerading as volunteers.exe. Fuery supports process injection via thread context hijacking, host reconnaissance, file operations, anti-analysis checks, and raw WinSock-based communications. The reporting also notes that the Fuery C2 shared a /24 subnet with known Phorpiex infrastructure on OMEGATECH LTD, suggesting either shared bulletproof hosting or possible operational overlap. Known aliases and identifiers directly mentioned in the reporting include ingermany, German Ingrmen, and the organization string ingermany. The reporting further concludes this actor is likely distinct from CERT-UA’s UAC-0006 based on registrar, hosting, and targeting differences.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator/developer linked by static analysis to Fuery and a related SmokeLoader variant through a shared Go obfuscation framework using Raft and VP8/VP9 cover types.
Operator behind a live SmokeLoader and Fuery botnet operation, using custom C2 infrastructure, a Flask-based panel disguised as "InsureFlow Pro," and shared tooling including novel Go obfuscation. The report assesses this actor as likely an independent SmokeLoader customer rather than UAC-0006.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.