Skip to content

Campaign record

UNK_RemoteRogue using Empire

Empire C2 delivered by a spoofed Microsoft Office document page

Status as last assessed
Dormant
First seen
2024-12-09
Last seen
2024-12-09
Indicators
5
Sources
1
Targets
Windows
  • Spoofed Microsoft Office document
  • Empire
  • Compromised mail server relay
  • Spearphishing link

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

A suspected Russian cluster Proofpoint labels UNK_RemoteRogue sent ten messages with no subject line on 9 December 2024, to people at two firms tied to a large defence manufacturer. The mail travelled through hacked Zimbra servers, which supplied the sender addresses, and carried a link on a domain imitating Microsoft's online office suite, with Ukrainian text describing it. Visiting the link produced a page mocked up as a Word document, with Russian instructions telling the reader to copy code out of the browser into a terminal; a YouTube tutorial on running PowerShell was linked for anyone unsure. What ran was JavaScript, which in turn launched PowerShell tied to the Empire post-exploitation framework. Proofpoint saw the group try this once, then revert to its usual approach: by late January 2025 that meant sending RDP configuration files mapping every local drive to a remote host.

Execution mechanisms

The only execution mechanism any published account describes for this campaign is PowerShell (T1059.001), which 19 of the 44 published campaigns in this corpus also record (43%).

Indicators

5 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “UNK_RemoteRogue using Empire”, campaign ID d48c97cd, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/d48c97cd/unk-remoterogue-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.