ComicForm
0 incidentes
0 paises
0 sectores
apt null Ultimo: -
ComicForm is a cyber threat actor first observed in April 2025, specializing in targeted phishing campaigns primarily against organizations in Eurasian countries like Belarus, Kazakhstan, and Russia. This group's primary motivation is to steal sensitive data and user credentials. A defining characteristic that sets ComicForm apart is their unique practice of embedding Tumblr links to innocuous comic superhero GIFs within their malware binaries, which also serves as the origin of their name. Although they operate concurrently in the same region and deploy similar malware, ComicForm is explicitly identified as distinct from the pro-Russian group SectorJ149.