HOMETHREATSKasablanka
APT / THREAT GROUP

Kasablanka

🇲🇦MA-attributed
1
campaigns
1
aliases
Last seen:Mar 17, 2026

Intelligence Profile

The Kasablanka group is a cyber-criminal organization that has

specifically targeted Russia between September and December 2022,

using various payloads delivered through phishing emails containing

socially engineered lnk files, zip packages, and executables attached to

virtual disk image files.

Threat Analysis

Kasablanka is a known-sophistication threat actor attributed to MA, engaged in cyber operations with a primary motivation of unknown activity patterns.

Known Campaigns

Kasablanka — Active Operations March 2026

Kasablanka is a unknown-motivation threat actor attributed to MA. The Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using various payloads delivered through phishing emails containing socially engineered lnk files, zip packages, and executables attached to virtual di...

ACTIVEMEDIUM2026

External References

Quick Facts

TypeAPT / Threat Group
Origin🇲🇦 MA
Aliases1
SourceMalpedia

Also Known As

Kasablanka

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.