GOFFEEGOFFEE

Also known as: GOFFEE

Known aliases
1

Profile

GOFFEE is a threat actor that has targeted entities in the Russian Federation since early 2022, employing spear phishing emails with malicious attachments, including modified Owowa and patched explorer.exe. They have utilized PowerTaskel, a non-public Mythic agent in PowerShell, and introduced a new implant called "PowerModul" for attacks against sectors such as media, telecommunications, and government. GOFFEE has increasingly shifted to a binary Mythic agent for lateral movement and has incorporated Word documents with malicious VBA scripts in their infection chains. The group has demonstrated a consistent evolution in their TTPs while maintaining identifiable characteristics that attribute their campaigns with high confidence.

Aliases· 1

GOFFEE

References

  1. https://securelist.com/goffee-apt-new-attacks/116139/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
DarkGaboon
Actor
GopherWhisper
Actor
Team46
Actor
UAC-0241
Actor
UAC-0226
Actor
BadRory
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.