Campaign record
UNK_RemoteRogue using Empire
Empire C2 delivered by a spoofed Microsoft Office document page
- Status as last assessed
- Dormant
- First seen
- 2024-12-09
- Last seen
- 2024-12-09
- Indicators
- 5
- Sources
- 1
- Targets
- Windows
- Spoofed Microsoft Office document
- Empire
- Compromised mail server relay
- Spearphishing link
Original research
- Proofpoint2025-04-16Vendor researchFirst account
Around the World in 90 Days: State-Sponsored Actors Try ClickFix
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
A suspected Russian cluster Proofpoint labels UNK_RemoteRogue sent ten messages with no subject line on 9 December 2024, to people at two firms tied to a large defence manufacturer. The mail travelled through hacked Zimbra servers, which supplied the sender addresses, and carried a link on a domain imitating Microsoft's online office suite, with Ukrainian text describing it. Visiting the link produced a page mocked up as a Word document, with Russian instructions telling the reader to copy code out of the browser into a terminal; a YouTube tutorial on running PowerShell was linked for anyone unsure. What ran was JavaScript, which in turn launched PowerShell tied to the Empire post-exploitation framework. Proofpoint saw the group try this once, then revert to its usual approach: by late January 2025 that meant sending RDP configuration files mapping every local drive to a remote host.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is PowerShell (T1059.001), which 19 of the 44 published campaigns in this corpus also record (43%).
Indicators
5 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “UNK_RemoteRogue using Empire”, campaign ID d48c97cd, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/d48c97cd/unk-remoterogue-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.