National Cyber Warfare Foundation (NCWF)

Scattered Spider


1 user ratings
2024-06-18 15:21:33
blscott

 - archive -- 

Scattered Spider

MITRE:  G1015

Scattered Spider is a native English-speaking cybercriminal group that has been active since at least 2022. The group initially targeted customer relationship management and business-process outsourcing (BPO) firms as well as telecommunications and technology companies. Beginning in 2023, Scattered Spider expanded its operations to compromise victims in the gaming, hospitality, retail, MSP, manufacturing, and financial sectors. During campaigns, Scattered Spider has leveraged targeted social-engineering techniques, attempted to bypass popular endpoint security tools, and more recently, deployed ransomware for financial gain.


Scattered Spider is an advanced persistent threat (APT) that has been identified by security researchers. It uses various techniques to evade detection and gain access to sensitive information, including using multiple domains for command-and-control communication, utilizing stealthy fileless malware, and employing sophisticated obfuscation methods. Scattered Spider is considered a high threat level due to its advanced tactics and potential impact on organizations in various industries. 

Techniques, tactics and practices:

Scattered Spider employs a variety of techniques to evade detection and gain access to sensitive information. These include using multiple domains for command-and-control communication, utilizing stealthy fileless malware that does not leave any files on the system, and employing sophisticated obfuscation methods such as encryption or encoding to hide their activities from security tools. Additionally, Scattered Spider is known to use various social engineering tactics to trick users into downloading and installing malicious software, including phishing emails that appear legitimate but are actually designed to steal sensitive information. Overall, the advanced nature of this APT highlights the need for organizations to implement robust security measures and stay vigilant against potential threats like Scattered Spider.

Source for information below - https://andreacristaldi.github.io/APTmap/

Scattered Spider, a highly active hacking group, has made
headlines by targeting more than 130 organizations, with the number of victims
steadily increasing. An affiliate group of \'ALPHV, BlackCat Gang\' (Mandiant)
UNC3944 is a financially motivated threat cluster that has persistently used
phone-based social engineering and SMS phishing campaigns (smishing) to obtain
credentials to gain and escalate access to victim organizations. At least some
UNC3944 threat actors appear to operate in underground communities, such as
Telegram and underground forums, which they may leverage to acquire tools,
services, and/or other support to augment their operations. 

This activity
overlaps with activity that has been reported in open sources as \'0ktapus,\'
\'Scatter Swine,\' and \'Scattered Spider.\' Since 2022 and through early 2023,
UNC3944 appeared to focus on accessing credentials or systems used to enable
SIM swapping attacks, likely in support of secondary criminal operations
occurring outside of victim environments. However, in mid-2023, UNC3944 began
to shift to deploying ransomware in victim environments, signaling an expansion
in the group\'s monetization strategies. These changes in their end goals signal
that the industries targeted by UNC3944 will continue to expand; Mandiant has
already directly observed their targeting broaden beyond telecommunication and
business process outsourcer (BPO) companies to a wide range of industries
including hospitality, retail, media and entertainment, and financial services.

(Palo Alto) Muddled Libra is a methodical adversary that
poses a substantial threat to organizations in the software automation, BPO,
telecommunications and technology industries. They are proficient in a range of
security disciplines, able to thrive in relatively secure environments and
execute rapidly to complete devastating attack chains. Muddled Libra doesn’t
bring anything new to the table except for the uncanny knack of stringing
together weaknesses to disastrous effect.

Defenders must combine cutting-edge technology and
comprehensive security hygiene, as well as diligent monitoring of external
threats and internal events. The high-stakes risk of loss of internal and
customer data is a strong incentive to modernize information security programs.

 Other names-

0ktapus, DEV-0971, LUCR-3, Muddled Libra, Octo Tempest,
Oktapus, Scatter Swine, Scattered Spider, Scattered Swine, Star Fraud,
Starfraud, Storm-0875, Storm-0971, UNC3944,

 First seen- 2022

 Target categories-

IT, Technology, Telecommunications,

Tools





















ADRecon (category:
Tools)


type: Reconnaissance

ADRecon is a tool which extracts and combines various artefacts (as highlighted
below) out of an AD environment. The information can be presented in a
specially formatted Microsoft Excel report that includes summary views with
metrics to facilitate analysis and provide a holistic picture of the current
state of the target AD environment.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=018bbbb7-5573-4940-b13c-8ff6eb2f3aeb

https://github.com/adrecon/ADRecon





AnyDesk (category:
Tools)


type: Backdoor

Access any device at any time. From anywhere. Always secure and fast.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a8ff6cf2-e406-445f-9365-861b3016a6bb

https://anydesk.com/





DCSync (category:
Malware)


type: Credential stealer

(Stealthbits) DCSync is a late-stage kill chain attack that allows an attacker
to simulate the behavior of Domain Controller (DC) in order to retrieve
password data via domain replication. Once an attacker has access to a
privileged account with domain replication rights, the attacker can utilize
replication protocols to mimic a domain controller. DCSync itself is a command
within \'Mimikatz\' and relies on utilizing specific commands within the
Microsoft Directory Replication Service Remote Protocol (MS-DRSR) to simulates
the behavior of a domain controller and asks other domain controllers to
replicate information by using the Directory Replication Service Remote
Protocol (MS-DRSR). Utilizing these protocols, this attack takes advantage of
valid and necessary functions of Active Directory, which cannot be turned off
or disabled.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7a686766-5739-4691-bc3a-3f6f8279ec28

https://blog.stealthbits.com/what-is-dcsync-an-introduction/





FiveTran (category:
Tools)


type: Info stealer

From startups to the Fortune 500 — for analytics or operations — Fivetran is
the trusted platform that extracts, loads and transforms the world\'s data.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7ad25688-4a6c-46a5-bb11-ebca71c86643

https://www.fivetran.com/





FleetDeck (category:
Tools)


type: Backdoor

FleetDeck is a new Remote Desktop & Virtual Terminal solution, tailored for
techs to securely manage large fleets of computers.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0ba4e9fb-ed7f-4f64-a50b-9f5b7a75f292

https://fleetdeck.io/





gosecretsdump (category:
Tools)


type: Credential stealer

This is a conversion of the \'Impacket\' secretsdump module into golang. It\'s not
very good, but it is quite fast. Please let me know if you find bugs, I\'ll try
and fix where I can - bonus points if you can provide sample .dit files for me
to bash against.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c6f10769-17f7-467f-8c1b-c2697fcd2ac9

https://github.com/C-Sto/gosecretsdump





Govmomi (category:
Tools)


type: Reconnaissance

A Go library for interacting with VMware vSphere APIs (ESXi and/or vCenter
Server).

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b4ee4d33-b23f-4a7d-a2cc-64c6c393df83

https://github.com/vmware/govmomi





Hekatomb (category:
Tools)


type: Credential stealer

Hekatomb is a python script that connects to LDAP directory to retrieve all
computers and users informations. Then it will download all DPAPI blob of all
users from all computers. Finally, it will extract domain controller private
key through RPC uses it to decrypt all credentials.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8bc73d19-39c1-47d6-afcc-1bf3f8227032

https://github.com/Processus-Thief/HEKATOMB





Impacket (category:
Tools)


type: Credential stealer, Info stealer

Impacket is an open source collection of modules written in Python for
programmatically constructing and manipulating network protocols. Impacket
contains several tools for remote service execution, Kerberos manipulation,
Windows credential dumping, packet sniffing, and relay attacks.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8e29a0d3-324b-43f0-b4f8-f81d18a2744e

https://github.com/SecureAuthCorp/impacket

https://attack.mitre.org/software/S0357/





LaZagne (category:
Tools)


type: Credential stealer

LaZagne is a post-exploitation, open-source tool used to recover stored
passwords on a system. It has modules for Windows, Linux, and OSX, but is
mainly focused on Windows systems. LaZagne is publicly available on GitHub.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f2697246-5288-4d3b-94d4-7200c85005e5

https://github.com/AlessandroZ/LaZagne

https://www.trendmicro.com/en_us/research/20/k/weaponizing-open-source-software-for-targeted-attacks.html

https://edu.anarcho-copy.org/Against%20Security%20&%20%20Self%20Security/Group-IB%20RedCurl.pdf

https://unit42.paloaltonetworks.com/lazagne-leverages-d-bus/

https://attack.mitre.org/software/S0349/

https://malpedia.caad.fkie.fraunhofer.de/details/py.lazagne

https://otx.alienvault.com/browse/pulses?q=tag:LazaGne





Living
off the Land (category: Tools)


(Talos) Attackers\' trends tend to come and go. But one popular technique we\'re
seeing at this time is the use of living-off-the-land binaries — or \'LoLBins\'.
LoLBins are used by different actors combined with fileless malware and
legitimate cloud services to improve chances of staying undetected within an
organisation, usually during post-exploitation attack phases.
Living-off-the-land tactics mean that attackers are using pre-installed tools
to carry out their work. This makes it more difficult for defenders to detect
attacks and researchers to identify the attackers behind the campaign. In the
attacks we\'re seeing, there are binaries supplied by the victim\'s operating
system that are normally used for legitimate purposes, but in these cases, are
being abused by the attackers. (LOLBAS Project) The goal of the LOLBAS project
is to document every binary, script, and library that can be used for Living
Off The Land techniques. A LOLBin/Lib/Script must: • Be a Microsoft-signed
file, either native to the OS or downloaded from Microsoft. • Have extra
\'unexpected\' functionality. It is not interesting to document intended use
cases. o Exceptions are application whitelisting bypasses • Have functionality
that would be useful to an APT or red team Interesting functionality can
include: • Executing code o Arbitrary code execution o Pass-through execution
of other programs (unsigned) or scripts (via a LOLBin) • Compiling code • File
operations o Downloading o Upload o Copy • Persistence o Pass-through
persistence utilizing existing LOLBin o Persistence (e.g. hide data in ADS,
execute at logon) • UAC bypass • Credential theft • Dumping process memory •
Surveillance (e.g. keylogger, network trace) • Log evasion/modification • DLL
side-loading/hijacking without being relocated elsewhere in the filesystem.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d54e09cf-97b7-40a4-b30e-4c0a2bf0ea40

https://github.com/LOLBAS-Project/LOLBAS

https://lolbas-project.github.io/

https://blog.talosintelligence.com/2019/11/hunting-for-lolbins.html

https://www.microsoft.com/security/blog/2021/03/09/azure-lolbins-protecting-against-the-dual-use-of-virtual-machine-extensions/

https://www.darkreading.com/edge-articles/is-an-attacker-living-off-your-land-

https://www.cybereason.com/blog/threat-hunting-from-lolbins-to-your-crown-jewels

https://pentera.io/blog/the-lol-isnt-so-funny-when-it-bites-you-in-the-bas/

https://www.darkreading.com/vulnerabilities-threats/as-lotl-attacks-evolve-so-must-defenses

https://otx.alienvault.com/browse/pulses?q=tag:lolbin





LummaC2 (category:
Malware)


type: Info stealer

(Cofense) Lumma Stealer, also known as LummaC2, is a subscription-based
information stealer that was first seen in 2022. It is written in C and has a
wide array of capabilities. This malware is primarily used for stealing
cryptocurrency wallets and sensitive information such as usernames and
passwords. Lumma Stealer also has the ability to deliver additional payloads.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b0283459-01a2-4745-bb9e-3ed188d0f1df

https://cofense.com/blog/luxury-hotels-remain-target-of-social-engineering-attack/

https://securelist.com/crimeware-report-asmcrypt-loader-lumma-stealer-zanubis-banker/110512/

https://outpost24.com/blog/lummac2-anti-sandbox-technique-trigonometry-human-detection/

https://perception-point.io/blog/behind-the-attack-lumma-malware/

https://www.fortinet.com/blog/threat-research/lumma-variant-on-youtube

https://www.ontinue.com/resource/obfuscated-powershell-leads-to-lumma-c2-stealer/

https://www.cloudsek.com/blog/unmasking-the-danger-lumma-stealer-malware-exploits-fake-captcha-pages

https://www.bitdefender.com/blog/hotforsecurity/lumma-stealer-campaign-targets-league-of-legends-world-championship-fans-through-social-media-ads/

https://blog.qualys.com/vulnerabilities-threat-research/2024/10/20/unmasking-lumma-stealer-analyzing-deceptive-tactics-with-fake-captcha

https://securelist.com/fake-captcha-delivers-lumma-amadey/114312/

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/lumma-stealer-on-the-rise-how-telegram-channels-are-fueling-malware-proliferation/

https://www.cybereason.com/blog/threat-analysis-rise-of-lummastealer

https://asec.ahnlab.com/en/85699/

https://www.bleepingcomputer.com/news/security/hundreds-of-fake-reddit-sites-push-lumma-stealer-malware/

https://www.netskope.com/blog/lumma-stealer-fake-captchas-new-techniques-to-evade-detection

https://www.trendmicro.com/en_us/research/25/a/lumma-stealers-github-based-delivery-via-mdr.html

https://www.cloudsek.com/blog/lumma-stealer-chronicles-pdf-themed-campaign-using-compromised-educational-institutions-infrastructure

https://asec.ahnlab.com/en/86435/





Mimikatz (category:
Tools)


type: Credential stealer, Keylogger

(SANS) Mimikatz provides a wealth of tools for collecting and making use of
Windows credentials on target systems, including retrieval of cleartext
passwords, Lan Manager hashes, and NTLM hashes, certificates, and Kerberos
tickets. The tools run with varying success on all versions of Windows from XP
forward, with functionality somewhat limited in Windows 8.1 and later.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8f0da519-c1bc-4add-9e04-2c429e74564f

https://github.com/gentilkiwi/mimikatz

https://www.sans.org/reading-room/whitepapers/intrusion/mimikatz-overview-defenses-detection-36780

https://www.wired.com/story/how-mimikatz-became-go-to-hacker-tool/

https://www.crowdstrike.com/blog/credential-theft-mimikatz-techniques/

https://attack.mitre.org/software/S0002/

https://malpedia.caad.fkie.fraunhofer.de/details/win.mimikatz

https://otx.alienvault.com/browse/pulses?q=tag:mimikatz





Ngrok (category:
Tools)


type: Backdoor, Tunneling

ngrok exposes local servers behind NATs and firewalls to the public internet
over secure tunnels.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1c06ef00-5e14-4693-8f44-371d6743b90e

https://ngrok.com/product

https://cyware.com/news/cyber-attackers-leverage-tunneling-service-to-drop-lokibot-onto-victims-systems-6f610e44

https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html

https://www.malwarebytes.com/resources/files/2021/02/lazyscripter.pdf

https://www.zdnet.com/article/sly-malware-author-hides-cryptomining-botnet-behind-ever-shifting-proxy-service/

https://attack.mitre.org/software/S0508/





PingCastle (category:
Tools)


type: Reconnaissance

Get Active Directory Security at 80% in 20% of the time

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=289962ef-49bd-4d80-b8d1-62425d0af14d

https://www.pingcastle.com/





ProcDump (category:
Tools)


type: Credential stealer

ProcDump is a command-line utility whose primary purpose is monitoring an
application for CPU spikes and generating crash dumps during a spike that an
administrator or developer can use to determine the cause of the spike.
ProcDump also includes hung window monitoring (using the same definition of a
window hang that Windows and Task Manager use), unhandled exception monitoring
and can generate dumps based on the values of system performance counters. It
also can serve as a general process dump utility that you can embed in other
scripts. Part of \'SysInternals\'.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bbc02c6f-31ae-404c-8e7c-75ed7b42600a

https://docs.microsoft.com/en-us/sysinternals/downloads/procdump





PsExec (category:
Tools)


type: Remote command

PsExec is a free Microsoft tool that can be used to execute a program on
another computer. It is used by IT administrators and attackers and is part of
\'SysInternals\'.



https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8bfdf3b6-764f-4b42-89e3-ec6c422fcf8a

https://docs.microsoft.com/en-us/sysinternals/downloads/psexec

https://www.bleepingcomputer.com/news/security/new-psexec-spinoff-lets-hackers-bypass-network-security-defenses/

https://attack.mitre.org/software/S0029/

https://otx.alienvault.com/browse/pulses?q=tag:psexec





Pulseway (category:
Tools)


type: Backdoor

Pulseway is an RMM software, built to help MSPs and IT teams reduce downtime
and set new standards for efficiency through automation.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=13fa72ca-7d48-4f86-94f7-e66dd476fab1

https://www.pulseway.com/





Pure
Storage FlashArray (category: Tools)


type: Reconnaissance

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1eee9db7-d17e-44c8-b1f9-553f9d1514ba

https://support.purestorage.com/Solutions/Microsoft_Platform_Guide/a_Windows_PowerShell/Pure_Storage_PowerShell_SDK





RedLine (category:
Malware)


type: Backdoor, Info stealer

(Cofense) RedLine Stealer, first seen in 2020, is probably the most well-known
stealer on this list. It uses Simple Object Access Protocol (SOAP) for
communication with its command-and-control center and can use a variety of
plugins. It’s used to collect information from various installed programs
including credentials stored in browsers, email applications, as well as
cryptocurrency wallet data. RedLine Stealer is often associated with
sophisticated phishing campaigns that, after a successful infection, can
deliver additional payloads like ransomware or more advanced malware.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=20c23064-7901-44cf-a07c-fe528fa60ab9

https://cofense.com/blog/luxury-hotels-remain-target-of-social-engineering-attack/

https://www.trendmicro.com/en_us/research/23/i/redline-vidar-first-abuses-ev-certificates.html

https://www.infosecurity-magazine.com/news/redline-stealer-malware-scrubcrypt/

https://unit42.paloaltonetworks.com/malware-configuration-extraction-techniques-guloader-redline-stealer/

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/redline-stealer-a-novel-approach/

https://www.bleepingcomputer.com/news/legal/redline-meta-infostealer-malware-operations-seized-by-police/

https://www.justice.gov/usao-wdtx/pr/us-joins-international-action-against-redline-and-meta-infostealers

https://www.welivesecurity.com/en/eset-research/life-crooked-redline-analyzing-infamous-infostealers-backend/





Rsocx (category:
Tools)


type: Tunneling

A high performence Socks5 proxy server with bind/reverse support

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1be0c744-24c9-4739-8ecf-23feb1559886

https://github.com/b23r0/rsocx





RustDesk (category:
Tools)


type: Backdoor

RustDesk is a full-featured open source remote control alternative for
self-hosting and security with minimal configuration.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8a617677-7b90-4fef-abd2-c408b2b77810

https://rustdesk.com/





ScreenConnect (category:
Tools)


type: Backdoor

Fast, flexible, and secure remote desktop and mobile support solutions for
every industry and need.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=99254ce6-d382-493e-8eec-615d813d5a8d

https://attack.mitre.org/software/S0591





SharpHound (category:
Malware)


type: Reconnaissance, Info stealer

C# Rewrite of the \'BloodHound\' Ingestor.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e6b2dbf6-0cea-40f8-98af-14ab4ad2ae27

https://github.com/BloodHoundAD/SharpHound3





Socat (category:
Tools)


type: Tunneling

Socat is a command line based utility that establishes two bidirectional byte
streams and transfers data between them. Because the streams can be constructed
from a large set of different types of data sinks and sources (see address
types), and because lots of address options may be applied to the streams,
socat can be used for many different purposes.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=918f02df-3f44-48f9-8e05-90c849c5484a

https://linux.die.net/man/1/socat





Spidey
Bot (category: Malware)


type: Info stealer, Credential stealer

(Cofense) Spidey Bot is a less common information stealer first seen in 2019.
It is designed to collect stored passwords and other data from a variety of
distinct sources within infected environments. The targeted information can
include VPN, internet browsers, email clients, gaming software, and
cryptocurrency.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e50a5bbe-cd91-4b89-9f4d-0e6351da8bb0

https://cofense.com/blog/luxury-hotels-remain-target-of-social-engineering-attack/





Splashtop (category:
Tools)


type: Backdoor

Secure, high-performance remote access at an unbeatable price

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=003204ac-54f8-4720-bd2d-77b29fc28679

https://www.splashtop.com/





Stealc (category:
Malware)


type: Info stealer

(Cofense) Stealc is a relatively new malware family that was first seen in
early 2023. It is known as a copycat information stealer because it has a suite
of features that is ostensibly based on \'VIDAR\', Raccoon, Mars, and \'RedLine\'
stealers. By default, Stealc targets data in web browsers, browser extensions,
cryptocurrency applications, and email messaging software.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b7d8fd6f-b51f-4edc-9f88-cbbc7f5cf920

https://cofense.com/blog/luxury-hotels-remain-target-of-social-engineering-attack/

https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc





TacticalRMM (category:
Tools)


type: Backdoor

Tactical RMM is a remote monitoring & management tool, built with Django
and Vue.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=69a45e94-f1ee-4a4a-b36f-e6e4d56f80ec

https://github.com/amidaware/tacticalrmm





Tailscale (category:
Tools)


type: Backdoor

Tailscale connects your team\'s devices and development environments for easy
access to remote resources.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e6d19f1b-02a0-4b65-a9e2-bb54f0ffe557

https://tailscale.com/





TightVNC (category:
Tools)


type: Backdoor

TightVNC is a free and Open Source remote desktop software that lets you access
and control a computer over the network.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5837a08c-4d32-4b58-8d6c-3112128fc0cf

https://www.tightvnc.com/





VIDAR (category:
Malware)


type: Info stealer, Credential stealer

Vidar is a forked malware based on Arkei. It seems this stealer is one of the
first that is grabbing information on 2FA Software and Tor Browser.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ebc3d7df-80c6-4979-ae55-1bac4823e315

https://www.cybereason.com/blog/the-hole-in-the-bucket-attackers-abuse-bitbucket-to-deliver-an-arsenal-of-malware

https://medium.com/s2wlab/w1-feb-en-story-of-the-week-stealers-on-the-darkweb-49945a31601d

https://www.bleepingcomputer.com/news/security/gandcrab-operators-use-vidar-infostealer-as-a-forerunner/

https://tccontre.blogspot.com/2019/03/infor-stealer-vidar-trojanspy-analysis.html

https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf

https://fumik0.com/2018/12/24/lets-dig-into-vidar-an-arkei-copycat-forked-stealer-in-depth-analysis/

https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/vidar-malware-launcher-concealed-in-help-file/

https://asec.ahnlab.com/en/44554/

https://thehackernews.com/2023/01/raccoon-and-vidar-stealers-spreading.html

https://www.team-cymru.com/post/darth-vidar-the-aesir-strike-back

https://www.trendmicro.com/en_us/research/23/i/redline-vidar-first-abuses-ev-certificates.html

https://asec.ahnlab.com/en/58750/

https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar





WinRAR (category:
Tools)


type: Compression

WinRAR is a data compression tool for Windows that focuses on RAR and ZIP
files. It also supports CAB, ARJ, LZH, TAR, Gzip, UUE, ISO, BZIP2, Z and 7-Zip.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=92f5812c-9f8a-4fcc-88cf-62308fc8fc0a

https://www.win-rar.com/





WsTunnel (category:
Tools)


type: Tunneling

Most of the time when you are using a public network, you are behind some kind
of firewall or proxy. One of their purpose is to constrain you to only use
certain kind of protocols. Nowadays, the most widespread protocol is http and
is de facto allowed by third party equipment.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4edc63bf-7c5f-47c3-b3b6-6413812f29c6

https://github.com/erebe/wstunnel





Comments
new comment
Nobody has commented yet. Will you be the first?


a.k.a
0ktapus
Octo Tempest
Roasted 0ktapus
Storm-0875
G1015
UNC3944
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.