‘The Manipulaters’ Improve Phishing, Still Fail at Opsec

Published on: 
April 3, 2024

The Resurgence of the “Manipulaters” Team - Breaking HeartSenders

In January 2024, The Manipulaters pleaded with Brian Krebs to unpublish previous stories about their work, claiming the group had turned over a new leaf and gone legitimate. But new research suggests that while they have improved the quality of their products and services, these nitwits still fail spectacularly at hiding their illegal activities.

https://krebsonsecurity.com/2024/04/the-manipulaters-improve-phishing-still-fail-at-opsec

Related Content

Research
Lemmings: A Russian Industrialized Persona Provisioning And Management for Active Measures Campaigns

Leaked internal data from Russian contractor Okenit reveals "Lemmings" (Лемминги)—a Python-based framework designed to industrialize the creation, verification, and management of synthetic online personas for Russian active measures. Built to automate phone verification, email infrastructure, CAPTCHA solving, and anti-detection measures, Lemmings functions as the identity-provisioning layer within a larger ecosystem alongside proxy and tasking tools (SOI and SOS). Live tests against platforms like VK and Reddit demonstrate a shift toward scalable, modular software frameworks capable of maintaining durable cover identities for intelligence, influence, and disinformation operations.

Learn More
Research
Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline

A leaked cache of institutional files reveals that Department No. 4 at Bauman Moscow State Technical University operates as a structured force-generation pipeline for Russian military cyber operations, training roughly 250 students across specializations. Supervised directly by senior GRU leadership, the program blends offensive intrusion, malware analysis, financial-systems targeting, and cryptographic defense with field placements that feed graduates straight into GRU- linked cyber formations like APT28 (Unit 26165) and Sandworm (Unit 74455).

Learn More
Research
Chinese Malware Delivery Domains Part V

Despite law enforcement arrests targeting the Silver Fox threat group in mid-June 2026, its malware delivery network remains active as a Malware-as-a-Service (MaaS) platform. Affiliates continue to deploy hundreds of new typosquatted domains and exploit major cloud services to distribute an obfuscated Gh0stRAT variant.

Learn More