Threat Intelligence / Actor / CityOfSin
CityOfSin
As of 2026-07-21, CityOfSin is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning supply chain. Also known as Backdoor.Win64.Alien operator, UNC-d_coroner (CityOfSin campaign), CityOfSin operator, FileZilla masquerading group.
Also known as: Backdoor.Win64.Alien operator, UNC-d_coroner (CityOfSin campaign), @d_coroner, CityOfSin operator, FileZilla masquerading group, supp0v3 operator
Tracked threats
- CPUID Supply Chain Attack Delivers STX RAT via Trojanized CPU-Z, HWMonitor, and PerfMonitor Downloads — CRITICAL
- CPUID Supply Chain Compromise — Trojanized CPU-Z 2.19, HWMonitor 1.63, PerfMonitor 2, and powerMAX Installers Distributed via Compromised cpuid.com API — CRITICAL
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →