PULSE NAME
Marko Polo Navigates Uncharted Waters with Infostealer Empire
WHITE Marko Polo AlienVault 2024-09-17 Modified: 2024-11-06
129
IOCs
HIGH VOLUME
An analysis has uncovered a highly adaptable cybercriminal group, codenamed 'Marko Polo', that operates sophisticated scams employing information-stealing malware to target individuals and organizations globally. They primarily operate through social media, impersonating legitimate brands in sectors like online gaming, virtual meetings, productivity software, and cryptocurrency. Their extensive operation involves over 30 distinct scams, 50 malware payloads, numerous malicious domains, and hundreds of fraudulent social media accounts. This widespread campaign likely compromised tens of thousands of devices globally, exposing sensitive personal and corporate data, posing risks to consumer privacy and business continuity while generating substantial illicit revenue.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Stealc Rhadamanthys HijackLoader
Indicators of Compromise (3 / 129 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0defc6f478324d079a54245f147a0680 2024-09-17
FileHash-MD5 68bced64ec1e8f57243c4f04e8fc5fb0 2024-09-17
FileHash-MD5 723ace88c71b9753939a5395eead3de1 2024-09-17