Striker
Striker is a cybercrime operator associated with the Striker C2 framework and, based on the provided reporting, has expanded from Striker C2 framework deployment into trojanized software distribution using signed RustDesk payloads. Breakglass Intelligence linked infrastructure used in a trojanized Microsoft Teams installer campaign to the previously identified GeorgeGinx/Striker operator through shared EvoXT hosting, a TLS certificate for calipology[.]com, and overlap with the "calipology" Telegram attribution. The campaign involved MSTeamsSetup.exe, a trojanized Microsoft Teams installer that delivered a weaponized RustDesk remote access client and used mon.systemautoupdater[.]com, resolving to 23.27.141[.]44, as active command-and-control infrastructure. The malware sample was signed with a suspicious Certum-issued code-signing certificate for "Zlatin Stamatov," assessed in the reporting as likely stolen or fraudulently obtained. The infrastructure at 23.27.141[.]44 exposed multiple services including FTP, SSH, Apache/nginx web services, and a Python-hosted "Trading Bots Management" panel on port 3004, suggesting broader criminal activity beyond remote access malware distribution. Known aliases and linked naming in the provided content include Striker, GeorgeGinx, and the "calipology" handle.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Observables
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.