Skip to content
skopnix
← adversaries
Unknown · assessed origin Russia

Operation Emmental

Retefe GangRetefe Group
misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

Operation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012. They primarily target customers of banks in countries such as Austria, Sweden, Switzerland, and Japan. The group has developed sophisticated malware, including a Mac alternative called Dok, to bypass two-factor authentication and hijack network traffic.

They have also been observed using phishing emails to spread their malware. The group is believed to be Russian-speaking and has continuously improved their malicious codes over the years.

Take it with you
References
Early access

Track Operation Emmental on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected