Scattered Spider
MITRE: G1015Scattered Spider is a native English-speaking cybercriminal group that has been active since at least 2022. The group initially targeted customer relationship management and business-process outsourcing (BPO) firms as well as telecommunications and technology companies. Beginning in 2023, Scattered Spider expanded its operations to compromise victims in the gaming, hospitality, retail, MSP, manufacturing, and financial sectors. During campaigns, Scattered Spider has leveraged targeted social-engineering techniques, attempted to bypass popular endpoint security tools, and more recently, deployed ransomware for financial gain.
Scattered Spider is an advanced persistent threat (APT) that has been identified by security researchers. It uses various techniques to evade detection and gain access to sensitive information, including using multiple domains for command-and-control communication, utilizing stealthy fileless malware, and employing sophisticated obfuscation methods. Scattered Spider is considered a high threat level due to its advanced tactics and potential impact on organizations in various industries.
Techniques, tactics and practices:
Scattered Spider employs a variety of techniques to evade detection and gain access to sensitive information. These include using multiple domains for command-and-control communication, utilizing stealthy fileless malware that does not leave any files on the system, and employing sophisticated obfuscation methods such as encryption or encoding to hide their activities from security tools. Additionally, Scattered Spider is known to use various social engineering tactics to trick users into downloading and installing malicious software, including phishing emails that appear legitimate but are actually designed to steal sensitive information. Overall, the advanced nature of this APT highlights the need for organizations to implement robust security measures and stay vigilant against potential threats like Scattered Spider.
Source for information below - https://andreacristaldi.github.io/APTmap/
Scattered Spider, a highly active hacking group, has made
headlines by targeting more than 130 organizations, with the number of victims
steadily increasing. An affiliate group of \'ALPHV, BlackCat Gang\' (Mandiant)
UNC3944 is a financially motivated threat cluster that has persistently used
phone-based social engineering and SMS phishing campaigns (smishing) to obtain
credentials to gain and escalate access to victim organizations. At least some
UNC3944 threat actors appear to operate in underground communities, such as
Telegram and underground forums, which they may leverage to acquire tools,
services, and/or other support to augment their operations.
This activity
overlaps with activity that has been reported in open sources as \'0ktapus,\'
\'Scatter Swine,\' and \'Scattered Spider.\' Since 2022 and through early 2023,
UNC3944 appeared to focus on accessing credentials or systems used to enable
SIM swapping attacks, likely in support of secondary criminal operations
occurring outside of victim environments. However, in mid-2023, UNC3944 began
to shift to deploying ransomware in victim environments, signaling an expansion
in the group\'s monetization strategies. These changes in their end goals signal
that the industries targeted by UNC3944 will continue to expand; Mandiant has
already directly observed their targeting broaden beyond telecommunication and
business process outsourcer (BPO) companies to a wide range of industries
including hospitality, retail, media and entertainment, and financial services.
(Palo Alto) Muddled Libra is a methodical adversary that
poses a substantial threat to organizations in the software automation, BPO,
telecommunications and technology industries. They are proficient in a range of
security disciplines, able to thrive in relatively secure environments and
execute rapidly to complete devastating attack chains. Muddled Libra doesn’t
bring anything new to the table except for the uncanny knack of stringing
together weaknesses to disastrous effect.
Defenders must combine cutting-edge technology and
comprehensive security hygiene, as well as diligent monitoring of external
threats and internal events. The high-stakes risk of loss of internal and
customer data is a strong incentive to modernize information security programs.
Other names-
0ktapus, DEV-0971, LUCR-3, Muddled Libra, Octo Tempest,
Oktapus, Scatter Swine, Scattered Spider, Scattered Swine, Star Fraud,
Starfraud, Storm-0875, Storm-0971, UNC3944,
First seen- 2022
Target categories-
IT, Technology, Telecommunications,
Tools
ADRecon (category:
Tools)
type: Reconnaissance
ADRecon is a tool which extracts and combines various artefacts (as highlighted
below) out of an AD environment. The information can be presented in a
specially formatted Microsoft Excel report that includes summary views with
metrics to facilitate analysis and provide a holistic picture of the current
state of the target AD environment.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=018bbbb7-5573-4940-b13c-8ff6eb2f3aeb
https://github.com/adrecon/ADRecon
AnyDesk (category:
Tools)
type: Backdoor
Access any device at any time. From anywhere. Always secure and fast.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a8ff6cf2-e406-445f-9365-861b3016a6bb
https://anydesk.com/
DCSync (category:
Malware)
type: Credential stealer
(Stealthbits) DCSync is a late-stage kill chain attack that allows an attacker
to simulate the behavior of Domain Controller (DC) in order to retrieve
password data via domain replication. Once an attacker has access to a
privileged account with domain replication rights, the attacker can utilize
replication protocols to mimic a domain controller. DCSync itself is a command
within \'Mimikatz\' and relies on utilizing specific commands within the
Microsoft Directory Replication Service Remote Protocol (MS-DRSR) to simulates
the behavior of a domain controller and asks other domain controllers to
replicate information by using the Directory Replication Service Remote
Protocol (MS-DRSR). Utilizing these protocols, this attack takes advantage of
valid and necessary functions of Active Directory, which cannot be turned off
or disabled.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7a686766-5739-4691-bc3a-3f6f8279ec28
https://blog.stealthbits.com/what-is-dcsync-an-introduction/
FiveTran (category:
Tools)
type: Info stealer
From startups to the Fortune 500 — for analytics or operations — Fivetran is
the trusted platform that extracts, loads and transforms the world\'s data.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7ad25688-4a6c-46a5-bb11-ebca71c86643
https://www.fivetran.com/
FleetDeck (category:
Tools)
type: Backdoor
FleetDeck is a new Remote Desktop & Virtual Terminal solution, tailored for
techs to securely manage large fleets of computers.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0ba4e9fb-ed7f-4f64-a50b-9f5b7a75f292
https://fleetdeck.io/
gosecretsdump (category:
Tools)
type: Credential stealer
This is a conversion of the \'Impacket\' secretsdump module into golang. It\'s not
very good, but it is quite fast. Please let me know if you find bugs, I\'ll try
and fix where I can - bonus points if you can provide sample .dit files for me
to bash against.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c6f10769-17f7-467f-8c1b-c2697fcd2ac9
https://github.com/C-Sto/gosecretsdump
Govmomi (category:
Tools)
type: Reconnaissance
A Go library for interacting with VMware vSphere APIs (ESXi and/or vCenter
Server).
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b4ee4d33-b23f-4a7d-a2cc-64c6c393df83
https://github.com/vmware/govmomi
Hekatomb (category:
Tools)
type: Credential stealer
Hekatomb is a python script that connects to LDAP directory to retrieve all
computers and users informations. Then it will download all DPAPI blob of all
users from all computers. Finally, it will extract domain controller private
key through RPC uses it to decrypt all credentials.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8bc73d19-39c1-47d6-afcc-1bf3f8227032
https://github.com/Processus-Thief/HEKATOMB
Impacket (category:
Tools)
type: Credential stealer, Info stealer
Impacket is an open source collection of modules written in Python for
programmatically constructing and manipulating network protocols. Impacket
contains several tools for remote service execution, Kerberos manipulation,
Windows credential dumping, packet sniffing, and relay attacks.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8e29a0d3-324b-43f0-b4f8-f81d18a2744e
https://github.com/SecureAuthCorp/impacket
https://attack.mitre.org/software/S0357/
LaZagne (category:
Tools)
type: Credential stealer
LaZagne is a post-exploitation, open-source tool used to recover stored
passwords on a system. It has modules for Windows, Linux, and OSX, but is
mainly focused on Windows systems. LaZagne is publicly available on GitHub.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f2697246-5288-4d3b-94d4-7200c85005e5
https://github.com/AlessandroZ/LaZagne
https://www.trendmicro.com/en_us/research/20/k/weaponizing-open-source-software-for-targeted-attacks.html
https://edu.anarcho-copy.org/Against%20Security%20&%20%20Self%20Security/Group-IB%20RedCurl.pdf
https://unit42.paloaltonetworks.com/lazagne-leverages-d-bus/
https://attack.mitre.org/software/S0349/
https://malpedia.caad.fkie.fraunhofer.de/details/py.lazagne
https://otx.alienvault.com/browse/pulses?q=tag:LazaGne
Living
off the Land (category: Tools)
(Talos) Attackers\' trends tend to come and go. But one popular technique we\'re
seeing at this time is the use of living-off-the-land binaries — or \'LoLBins\'.
LoLBins are used by different actors combined with fileless malware and
legitimate cloud services to improve chances of staying undetected within an
organisation, usually during post-exploitation attack phases.
Living-off-the-land tactics mean that attackers are using pre-installed tools
to carry out their work. This makes it more difficult for defenders to detect
attacks and researchers to identify the attackers behind the campaign. In the
attacks we\'re seeing, there are binaries supplied by the victim\'s operating
system that are normally used for legitimate purposes, but in these cases, are
being abused by the attackers. (LOLBAS Project) The goal of the LOLBAS project
is to document every binary, script, and library that can be used for Living
Off The Land techniques. A LOLBin/Lib/Script must: • Be a Microsoft-signed
file, either native to the OS or downloaded from Microsoft. • Have extra
\'unexpected\' functionality. It is not interesting to document intended use
cases. o Exceptions are application whitelisting bypasses • Have functionality
that would be useful to an APT or red team Interesting functionality can
include: • Executing code o Arbitrary code execution o Pass-through execution
of other programs (unsigned) or scripts (via a LOLBin) • Compiling code • File
operations o Downloading o Upload o Copy • Persistence o Pass-through
persistence utilizing existing LOLBin o Persistence (e.g. hide data in ADS,
execute at logon) • UAC bypass • Credential theft • Dumping process memory •
Surveillance (e.g. keylogger, network trace) • Log evasion/modification • DLL
side-loading/hijacking without being relocated elsewhere in the filesystem.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d54e09cf-97b7-40a4-b30e-4c0a2bf0ea40
https://github.com/LOLBAS-Project/LOLBAS
https://lolbas-project.github.io/
https://blog.talosintelligence.com/2019/11/hunting-for-lolbins.html
https://www.microsoft.com/security/blog/2021/03/09/azure-lolbins-protecting-against-the-dual-use-of-virtual-machine-extensions/
https://www.darkreading.com/edge-articles/is-an-attacker-living-off-your-land-
https://www.cybereason.com/blog/threat-hunting-from-lolbins-to-your-crown-jewels
https://pentera.io/blog/the-lol-isnt-so-funny-when-it-bites-you-in-the-bas/
https://www.darkreading.com/vulnerabilities-threats/as-lotl-attacks-evolve-so-must-defenses
https://otx.alienvault.com/browse/pulses?q=tag:lolbin
LummaC2 (category:
Malware)
type: Info stealer
(Cofense) Lumma Stealer, also known as LummaC2, is a subscription-based
information stealer that was first seen in 2022. It is written in C and has a
wide array of capabilities. This malware is primarily used for stealing
cryptocurrency wallets and sensitive information such as usernames and
passwords. Lumma Stealer also has the ability to deliver additional payloads.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b0283459-01a2-4745-bb9e-3ed188d0f1df
https://cofense.com/blog/luxury-hotels-remain-target-of-social-engineering-attack/
https://securelist.com/crimeware-report-asmcrypt-loader-lumma-stealer-zanubis-banker/110512/
https://outpost24.com/blog/lummac2-anti-sandbox-technique-trigonometry-human-detection/
https://perception-point.io/blog/behind-the-attack-lumma-malware/
https://www.fortinet.com/blog/threat-research/lumma-variant-on-youtube
https://www.ontinue.com/resource/obfuscated-powershell-leads-to-lumma-c2-stealer/
https://www.cloudsek.com/blog/unmasking-the-danger-lumma-stealer-malware-exploits-fake-captcha-pages
https://www.bitdefender.com/blog/hotforsecurity/lumma-stealer-campaign-targets-league-of-legends-world-championship-fans-through-social-media-ads/
https://blog.qualys.com/vulnerabilities-threat-research/2024/10/20/unmasking-lumma-stealer-analyzing-deceptive-tactics-with-fake-captcha
https://securelist.com/fake-captcha-delivers-lumma-amadey/114312/
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/lumma-stealer-on-the-rise-how-telegram-channels-are-fueling-malware-proliferation/
https://www.cybereason.com/blog/threat-analysis-rise-of-lummastealer
https://asec.ahnlab.com/en/85699/
https://www.bleepingcomputer.com/news/security/hundreds-of-fake-reddit-sites-push-lumma-stealer-malware/
https://www.netskope.com/blog/lumma-stealer-fake-captchas-new-techniques-to-evade-detection
https://www.trendmicro.com/en_us/research/25/a/lumma-stealers-github-based-delivery-via-mdr.html
https://www.cloudsek.com/blog/lumma-stealer-chronicles-pdf-themed-campaign-using-compromised-educational-institutions-infrastructure
https://asec.ahnlab.com/en/86435/
Mimikatz (category:
Tools)
type: Credential stealer, Keylogger
(SANS) Mimikatz provides a wealth of tools for collecting and making use of
Windows credentials on target systems, including retrieval of cleartext
passwords, Lan Manager hashes, and NTLM hashes, certificates, and Kerberos
tickets. The tools run with varying success on all versions of Windows from XP
forward, with functionality somewhat limited in Windows 8.1 and later.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8f0da519-c1bc-4add-9e04-2c429e74564f
https://github.com/gentilkiwi/mimikatz
https://www.sans.org/reading-room/whitepapers/intrusion/mimikatz-overview-defenses-detection-36780
https://www.wired.com/story/how-mimikatz-became-go-to-hacker-tool/
https://www.crowdstrike.com/blog/credential-theft-mimikatz-techniques/
https://attack.mitre.org/software/S0002/
https://malpedia.caad.fkie.fraunhofer.de/details/win.mimikatz
https://otx.alienvault.com/browse/pulses?q=tag:mimikatz
Ngrok (category:
Tools)
type: Backdoor, Tunneling
ngrok exposes local servers behind NATs and firewalls to the public internet
over secure tunnels.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1c06ef00-5e14-4693-8f44-371d6743b90e
https://ngrok.com/product
https://cyware.com/news/cyber-attackers-leverage-tunneling-service-to-drop-lokibot-onto-victims-systems-6f610e44
https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html
https://www.malwarebytes.com/resources/files/2021/02/lazyscripter.pdf
https://www.zdnet.com/article/sly-malware-author-hides-cryptomining-botnet-behind-ever-shifting-proxy-service/
https://attack.mitre.org/software/S0508/
PingCastle (category:
Tools)
type: Reconnaissance
Get Active Directory Security at 80% in 20% of the time
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=289962ef-49bd-4d80-b8d1-62425d0af14d
https://www.pingcastle.com/
ProcDump (category:
Tools)
type: Credential stealer
ProcDump is a command-line utility whose primary purpose is monitoring an
application for CPU spikes and generating crash dumps during a spike that an
administrator or developer can use to determine the cause of the spike.
ProcDump also includes hung window monitoring (using the same definition of a
window hang that Windows and Task Manager use), unhandled exception monitoring
and can generate dumps based on the values of system performance counters. It
also can serve as a general process dump utility that you can embed in other
scripts. Part of \'SysInternals\'.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bbc02c6f-31ae-404c-8e7c-75ed7b42600a
https://docs.microsoft.com/en-us/sysinternals/downloads/procdump
PsExec (category:
Tools)
type: Remote command
PsExec is a free Microsoft tool that can be used to execute a program on
another computer. It is used by IT administrators and attackers and is part of
\'SysInternals\'.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8bfdf3b6-764f-4b42-89e3-ec6c422fcf8a
https://docs.microsoft.com/en-us/sysinternals/downloads/psexec
https://www.bleepingcomputer.com/news/security/new-psexec-spinoff-lets-hackers-bypass-network-security-defenses/
https://attack.mitre.org/software/S0029/
https://otx.alienvault.com/browse/pulses?q=tag:psexec
Pulseway (category:
Tools)
type: Backdoor
Pulseway is an RMM software, built to help MSPs and IT teams reduce downtime
and set new standards for efficiency through automation.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=13fa72ca-7d48-4f86-94f7-e66dd476fab1
https://www.pulseway.com/
Pure
Storage FlashArray (category: Tools)
type: Reconnaissance
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1eee9db7-d17e-44c8-b1f9-553f9d1514ba
https://support.purestorage.com/Solutions/Microsoft_Platform_Guide/a_Windows_PowerShell/Pure_Storage_PowerShell_SDK
RedLine (category:
Malware)
type: Backdoor, Info stealer
(Cofense) RedLine Stealer, first seen in 2020, is probably the most well-known
stealer on this list. It uses Simple Object Access Protocol (SOAP) for
communication with its command-and-control center and can use a variety of
plugins. It’s used to collect information from various installed programs
including credentials stored in browsers, email applications, as well as
cryptocurrency wallet data. RedLine Stealer is often associated with
sophisticated phishing campaigns that, after a successful infection, can
deliver additional payloads like ransomware or more advanced malware.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=20c23064-7901-44cf-a07c-fe528fa60ab9
https://cofense.com/blog/luxury-hotels-remain-target-of-social-engineering-attack/
https://www.trendmicro.com/en_us/research/23/i/redline-vidar-first-abuses-ev-certificates.html
https://www.infosecurity-magazine.com/news/redline-stealer-malware-scrubcrypt/
https://unit42.paloaltonetworks.com/malware-configuration-extraction-techniques-guloader-redline-stealer/
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/redline-stealer-a-novel-approach/
https://www.bleepingcomputer.com/news/legal/redline-meta-infostealer-malware-operations-seized-by-police/
https://www.justice.gov/usao-wdtx/pr/us-joins-international-action-against-redline-and-meta-infostealers
https://www.welivesecurity.com/en/eset-research/life-crooked-redline-analyzing-infamous-infostealers-backend/
Rsocx (category:
Tools)
type: Tunneling
A high performence Socks5 proxy server with bind/reverse support
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1be0c744-24c9-4739-8ecf-23feb1559886
https://github.com/b23r0/rsocx
RustDesk (category:
Tools)
type: Backdoor
RustDesk is a full-featured open source remote control alternative for
self-hosting and security with minimal configuration.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8a617677-7b90-4fef-abd2-c408b2b77810
https://rustdesk.com/
ScreenConnect (category:
Tools)
type: Backdoor
Fast, flexible, and secure remote desktop and mobile support solutions for
every industry and need.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=99254ce6-d382-493e-8eec-615d813d5a8d
https://attack.mitre.org/software/S0591
SharpHound (category:
Malware)
type: Reconnaissance, Info stealer
C# Rewrite of the \'BloodHound\' Ingestor.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e6b2dbf6-0cea-40f8-98af-14ab4ad2ae27
https://github.com/BloodHoundAD/SharpHound3
Socat (category:
Tools)
type: Tunneling
Socat is a command line based utility that establishes two bidirectional byte
streams and transfers data between them. Because the streams can be constructed
from a large set of different types of data sinks and sources (see address
types), and because lots of address options may be applied to the streams,
socat can be used for many different purposes.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=918f02df-3f44-48f9-8e05-90c849c5484a
https://linux.die.net/man/1/socat
Spidey
Bot (category: Malware)
type: Info stealer, Credential stealer
(Cofense) Spidey Bot is a less common information stealer first seen in 2019.
It is designed to collect stored passwords and other data from a variety of
distinct sources within infected environments. The targeted information can
include VPN, internet browsers, email clients, gaming software, and
cryptocurrency.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e50a5bbe-cd91-4b89-9f4d-0e6351da8bb0
https://cofense.com/blog/luxury-hotels-remain-target-of-social-engineering-attack/
Splashtop (category:
Tools)
type: Backdoor
Secure, high-performance remote access at an unbeatable price
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=003204ac-54f8-4720-bd2d-77b29fc28679
https://www.splashtop.com/
Stealc (category:
Malware)
type: Info stealer
(Cofense) Stealc is a relatively new malware family that was first seen in
early 2023. It is known as a copycat information stealer because it has a suite
of features that is ostensibly based on \'VIDAR\', Raccoon, Mars, and \'RedLine\'
stealers. By default, Stealc targets data in web browsers, browser extensions,
cryptocurrency applications, and email messaging software.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b7d8fd6f-b51f-4edc-9f88-cbbc7f5cf920
https://cofense.com/blog/luxury-hotels-remain-target-of-social-engineering-attack/
https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
TacticalRMM (category:
Tools)
type: Backdoor
Tactical RMM is a remote monitoring & management tool, built with Django
and Vue.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=69a45e94-f1ee-4a4a-b36f-e6e4d56f80ec
https://github.com/amidaware/tacticalrmm
Tailscale (category:
Tools)
type: Backdoor
Tailscale connects your team\'s devices and development environments for easy
access to remote resources.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e6d19f1b-02a0-4b65-a9e2-bb54f0ffe557
https://tailscale.com/
TightVNC (category:
Tools)
type: Backdoor
TightVNC is a free and Open Source remote desktop software that lets you access
and control a computer over the network.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5837a08c-4d32-4b58-8d6c-3112128fc0cf
https://www.tightvnc.com/
VIDAR (category:
Malware)
type: Info stealer, Credential stealer
Vidar is a forked malware based on Arkei. It seems this stealer is one of the
first that is grabbing information on 2FA Software and Tor Browser.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ebc3d7df-80c6-4979-ae55-1bac4823e315
https://www.cybereason.com/blog/the-hole-in-the-bucket-attackers-abuse-bitbucket-to-deliver-an-arsenal-of-malware
https://medium.com/s2wlab/w1-feb-en-story-of-the-week-stealers-on-the-darkweb-49945a31601d
https://www.bleepingcomputer.com/news/security/gandcrab-operators-use-vidar-infostealer-as-a-forerunner/
https://tccontre.blogspot.com/2019/03/infor-stealer-vidar-trojanspy-analysis.html
https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf
https://fumik0.com/2018/12/24/lets-dig-into-vidar-an-arkei-copycat-forked-stealer-in-depth-analysis/
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/vidar-malware-launcher-concealed-in-help-file/
https://asec.ahnlab.com/en/44554/
https://thehackernews.com/2023/01/raccoon-and-vidar-stealers-spreading.html
https://www.team-cymru.com/post/darth-vidar-the-aesir-strike-back
https://www.trendmicro.com/en_us/research/23/i/redline-vidar-first-abuses-ev-certificates.html
https://asec.ahnlab.com/en/58750/
https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar
WinRAR (category:
Tools)
type: Compression
WinRAR is a data compression tool for Windows that focuses on RAR and ZIP
files. It also supports CAB, ARJ, LZH, TAR, Gzip, UUE, ISO, BZIP2, Z and 7-Zip.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=92f5812c-9f8a-4fcc-88cf-62308fc8fc0a
https://www.win-rar.com/
WsTunnel (category:
Tools)
type: Tunneling
Most of the time when you are using a public network, you are behind some kind
of firewall or proxy. One of their purpose is to constrain you to only use
certain kind of protocols. Nowadays, the most widespread protocol is http and
is de facto allowed by third party equipment.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4edc63bf-7c5f-47c3-b3b6-6413812f29c6
https://github.com/erebe/wstunnel
