PULSE NAME
Marko Polo Navigates Uncharted Waters with Infostealer Empire
WHITE Marko Polo AlienVault 2024-09-17 Modified: 2024-11-06
129
IOCs
HIGH VOLUME
An analysis has uncovered a highly adaptable cybercriminal group, codenamed 'Marko Polo', that operates sophisticated scams employing information-stealing malware to target individuals and organizations globally. They primarily operate through social media, impersonating legitimate brands in sectors like online gaming, virtual meetings, productivity software, and cryptocurrency. Their extensive operation involves over 30 distinct scams, 50 malware payloads, numerous malicious domains, and hundreds of fraudulent social media accounts. This widespread campaign likely compromised tens of thousands of devices globally, exposing sensitive personal and corporate data, posing risks to consumer privacy and business continuity while generating substantial illicit revenue.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Stealc Rhadamanthys HijackLoader
Indicators of Compromise (3 / 129 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 94513265b2448ebd88f8afc0ce77fd27a523f016 2024-09-17
FileHash-SHA1 d82b8b5f5e85a926cb6195cf75baa232bb5a2966 2024-09-17
FileHash-SHA1 f1719b1cf427afb31f91789e8fef8cbd77c5a613 2024-09-17