A suspected Russian threat actor known for phishing campaigns using compromised intermediate mailservers.
Analyst brief
UNK_RemoteRogue is a suspected Russian threat actor observed leveraging phishing campaigns with compromised intermediate mailservers. Their TTPs include the ClickFix social engineering technique and use of upstream concentrator infrastructure like 80.66.66.197, though they often revert to traditional installation methods. Defenders should monitor for traffic associated with the noted IP and scrutinize intermediate mailservers for anomalous access patterns.
UNK_RemoteRogue
unknown
UNK_RemoteRogue is a suspected Russian threat actor that has been observed utilizing ClickFix in its infection chains, although this technique is not revolutionizing their operations but rather replacing existing installation methods. The group has a history of employing compromised intermediate mailservers, with specific infrastructure noted, such as the upstream concentrator at 80.66.66[.]197. Proofpoint recorded their use of ClickFix only once before they reverted to traditional campaigns that share similar characteristics, including targeting and infrastructure. UNK_RemoteRogue has been linked to phishing activities and has shown consistent patterns in its operational tactics.