SHADOW-AETHER-015SHADOW-AETHER-015

Also known as: SHADOW-AETHER-015

Known aliases
1

Profile

SHADOW-AETHER-015 is a highly adaptable cybercriminal group known for identity abuse and cloud compromise, primarily targeting identity and access management systems like Okta and Azure AD/Entra ID. They employ sophisticated social engineering techniques, including vishing and help-desk impersonation, to gain access to legitimate credentials. Their operations involve multi-pressure extortion tactics, such as data theft, ransomware, and employee intimidation, while leveraging MFA fatigue and token theft to bypass authentication controls. The group has been linked to the "0ktapus" phishing campaign and is most active in English-speaking countries, with a focus on sectors rich in sensitive data.

Aliases· 1

SHADOW-AETHER-015

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Shadow-Earth-053
Actor
UAC-0215
Actor
Storm-0501
Actor
JavaGhost
Actor
APT15
Actor
SHADOW-VOID-042
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.