# Markas Escobar

> As of 2026-08-03, Markas Escobar is a Indonesia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. ATT&CK coverage spans 26 techniques across 10 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1014 (Rootkit), T1016 (System Network Configuration Discovery).

- **Nation:** Indonesia
- **Tracked threats:** 2
- **Categories:** MALWARE
- **As of:** 2026-08-03

## ATT&CK techniques observed

26 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (6), Discovery (4), Resource Development (4), Collection (2), Command and Control (2), Defense Impairment (2).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1014](https://intel.threadlinqs.com/technique/T1014) Rootkit — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 2 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 2 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1033](https://intel.threadlinqs.com/technique/T1033) System Owner/User Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1036.004](https://intel.threadlinqs.com/technique/T1036.004) Masquerade Task or Service — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 2 tracked threats
- [T1059.004](https://intel.threadlinqs.com/technique/T1059.004) Unix Shell — Execution — observed in 1 of 2 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 1 of 2 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 1 of 2 tracked threats

## Tracked threats

- [1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)](https://intel.threadlinqs.com/threat/TL-2026-1837) — HIGH
- [1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)](https://intel.threadlinqs.com/threat/TL-2026-1791) — MEDIUM

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Markas%20Escobar
