Y2K Operators
The threat cluster Group-IB tracks around active Millenium RAT deployment and distribution.
Who are the Y2K Operators? Y2K Operators is the name Group-IB uses to track a threat cluster associated with active Millenium RAT deployment and distribution campaigns. It is distinct from ShinyEnigma, the developer/marketing identity. The two should not automatically be treated as the same entity.
Threat-cluster profile
Group-IB tracks a threat cluster operating Millenium RAT under the name Y2K Operators. A threat cluster is a grouping of activity based on shared infrastructure, tooling, and behavior — not necessarily a confirmed organization or set of named individuals.
Developer vs. operators: a critical distinction
Associated with developing and selling Millenium RAT (the MaaS product).
Associated by Group-IB with active campaigns using Millenium RAT in the wild.
Do not automatically claim they are the same entity. Developers and operators of malware-as-a-service are frequently different groups.
- 01Tracking name: Y2K Operators
- 02Source: Group-IB
- 03Role: active deployment & distribution
- 04Distinct from: ShinyEnigma (developer)
- 05Scale context: 62,289 endpoints / 160+ countries
- 06Cluster ≠ confirmed organization
Associated campaign scope
Group-IB's campaign telemetry — attributed in scope to the broader Millenium RAT ecosystem the Y2K Operators cluster operates within — recorded 62,289 compromised endpoints across 160+ countries, with 39,730 infections in Q1 2026. India, the United States, and Brazil were highlighted among major affected geographies.
- ▸Y2K Operators is a Group-IB tracking name for an operational cluster.
- ▸Associated with active deployment and distribution of Millenium RAT.
- ▸Distinct from ShinyEnigma (development/marketing).
- ▸Cluster grouping is based on shared activity, not confirmed identity.

