Uptime Hamster: 10d 15h 47mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Operation Ghoul

Operation Ghoul

0 incidentes 0 paises 0 sectores apt UNKNOWN Ultimo: -
Aliases: ingeniería, manufactura en más de 30 países
Ver en IntelTracker → APTTrail →
Operation Ghoul is a financially driven cybercriminal campaign identified by Kaspersky Lab, with activity first observed in March 2015. This group primarily targets small to medium-sized organizations across various sectors, including industrial, engineering, manufacturing, pharmaceutical, and educational services, in over 30 countries, with a notable focus on the Middle East. Their core motivation is financial gain, which they achieve by stealing intellectual property, sensitive business intelligence, and compromising banking accounts. What sets Operation Ghoul apart is its reliance on readily available commercial off-the-shelf malware, particularly HawkEye, distributed through convincing spear-phishing emails often impersonating legitimate financial institutions in the United Arab Emirates. This approach makes attribution more difficult and enables effective attacks against entities less prepared for such intrusions. While sometimes referred to as cyber espionage due to its data thef

Aliases del actor

ingenieríamanufactura en más de 30 países

Actores similares

dispossessorransomware · 344mosesstaffactor · 2apt-glassesactor · 1IP Addressesactor · 1Steal Web Session Cookieactor · 1Databasesactor · 1Operation Wocaoapt · 1Moses Staffactor · 1Impair Defenses: Disable or Modify Toolsactor · 1tortoiseshellactor · 1
Motivacion