Operation Emmental

Aliases: Retefe Gang, Retefe Group

First seen
2012-01-01 00:00:00
Origin
RU
Primary motivation
financial-gain
Sophistication
innovator
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:14:03

Targeted industries: financial-services

Targeted regions: country_code:at country_code:se country_code:ch country_code:jp

Context

Operation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012. They primarily target customers of banks in countries such as Austria, Sweden, Switzerland, and Japan. The group has developed sophisticated malware, including a Mac alternative called Dok, to bypass two-factor authentication and hijack network traffic. They have also been observed using phishing emails to spread their malware. The group is believed to be Russian-speaking and has continuously improved their malicious codes over the years.

Reports & references

  • Trend Micro — Osx Dok Mac Malware Emmental Hijacks User Network Traffic (report)

External references