Monthly Threat Actor Group Intelligence Report, October 2025

2025-11-07 NSHC

https://medium.com/@nshcthreatrecon/monthly-threat-actor-group-intelligence-report-october-2025-6a3ac29592cb

Thumbnail for Monthly Threat Actor Group Intelligence Report, October 2025

NSHC’s October 2025 intelligence roundup says SectorA activity used multi-stage social engineering against Windows, macOS, and Linux systems, with software developers and technical experts among the main targets. The SectorA section describes fake software updates, job offers, malicious payload distribution through GitHub, fake social-media profiles, phishing, and job-scam infrastructure. Reported malware includes BeaverTail, OtterCookie, and OtterCandy, used for system information collection, credential theft, data exfiltration, remote command execution, and financially motivated activity against cryptocurrency and Web3 projects. The excerpt also notes obfuscation, multi-stage C2 infrastructure, scheduler-based persistence, and PowerShell command execution, making the activity relevant to monitoring developer-focused supply-chain and crypto-theft tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ukr.net 2023-04-12 2026-04-02
DOMAIN ffrk.net 2025-11-07 2025-11-07

Related Actors

Related Reports

« Back