🇧🇾
Ghostwriter
APT Group
3 zero-day CVEs
ETDA ✓
Also Known As 6 names
DEV-0257
PUSHCHA
Storm-0257
TA445
UAC-0057
UNC1151
Target Countries 36
Countries highlighted in red
Australia
Belarus
Canada
Switzerland
China
Colombia
Germany
Estonia
Spain
France
United Kingdom
Ireland
India
Italy
Democratic People's Republic of Korea
Republic of Korea
Kuwait
Kazakhstan
Lithuania
Latvia
Mongolia
Malta
Mexico
Malaysia
New Zealand
Poland
Portugal
Romania
Serbia
Russian Federation
Sweden
Singapore
Thailand
Ukraine
United States
Vietnam
Sectors Targeted
Executive, Legislative, and Other General Government Support
9211
Military
Religious, Grantmaking, Civic, Professional, and Similar Organizations
813
Companies
power grids)
Private Sector
Manufacturing
Financial Sector
Military and Defense
Utilities
22
Infrastructure
Various Sectors
Critical Infrastructure
Cryptocurrency
Internet Publishing and Broadcasting and Web Search Portals
51913
Trade
Defense contractor
Energy
Critical Infrastructure (transportation
Defense contractors
Transportation
Non-profit
Health Care and Social Assistance
62
Public Administration
92
Multiple
Grantmaking and Giving Services
8132
Oil and Gas Extraction
211
Technology
News Media
Oil and Gas
Publishing Industries (except Internet)
511
National Security and International Affairs
928110
Retail
Couriers and Express Delivery Services
492110
Logistics
Computer Systems Design Services
541512
Social Media
National Security and International Affairs
928
Media Streaming Distribution Services, Social Networks, and Other Media Networks and Content Providers
5162
Other Information Services
519
Financial
Mining, Quarrying, and Oil and Gas Extraction
21
Economic
Commodity Contracts Intermediation
523160
Civilian
Electronic
Healthcare
Defence
Finance
NAICS:44
44
Public Sector
Media
Space Research and Technology
927
Activism
Organizations
Telecommunications
Business to Business Electronic Markets
42511
Translation and Interpretation Services
54193
Other Services (except Public Administration)
81
Customer Care
Telecommunications
517
Information
51
NGOs
Defense
Finance and Insurance
52
Water
Industrial
NAICS:31
31
Call Center
Pharmaceuticals
Research and Development in the Social Sciences and Humanities
54172
Commercial Banking
52211
Computer and Electronic Product Manufacturing
334
Chemical Manufacturing
325
communications
Political Entities
Journalists
Performing Arts Companies
7111
Professional, Scientific, and Technical Services
54
Computer Systems Design and Related Services
54151
All
Government
Periodical Publishers
51112
NAICS:48
48
Cybersecurity
Think tanks
Foreign Affairs
Banks
Arts, Entertainment, and Recreation
71
Educational Services
61
Diplomatic
Political Activism
Financial Services
Details
Origin
🇧🇾 BY
Last Updated
01 Jun 2022
Malware Families 6
graphsteel
grimplant
huskloader
NJRAT
COBALTSTRIKE
sunseed
MITRE ATT&CK 77
T1002
T1010
T1012 - Query Registry
T1016
T1027 - Obfuscated Files or Information
T1033 - System Owner/User Discovery
T1036 - Masquerading
T1041
T1046
T1053.005 - Scheduled Task
T1055 - Process Injection
T1056
T1057 - Process Discovery
T1059 - Command and Scripting Interpreter
T1059.001
T1059.003 - Windows Command Shell
T1059.005 - Visual Basic
T1059.007 - JavaScript
T1064
T1071
T1071.001 - Web Protocols
T1078 - Valid Accounts
T1082 - System Information Discovery
T1083 - File and Directory Discovery
T1087
T1100
T1102
T1102.002 - Bidirectional Communication
T1102.003 - One-Way Communication
T1104
T1105 - Ingress Tool Transfer
T1113
T1114 - Email Collection
T1114.001 - Local Email Collection
T1114.002 - Remote Email Collection
T1115
T1127 - Trusted Developer Utilities Proxy Execution
T1132.001 - Standard Encoding
T1137 - Office Application Startup
T1140 - Deobfuscate/Decode Files or Information
T1176 - Browser Extensions
T1189
T1190 - Exploit Public-Facing Application
T1193
T1203
T1204
T1204.002 - Malicious File
T1205 - Traffic Signaling
T1208
T1218
T1218.011 - Rundll32
T1219
T1221
T1471
T1482
T1486
T1497
T1518 - Software Discovery
T1518.001 - Security Software Discovery
T1539 - Steal Web Session Cookie
T1543
T1547
T1547.001 - Registry Run Keys / Startup Folder
T1555
T1560
T1564
T1566 - Phishing
T1566.001 - Spearphishing Attachment
T1573.001 - Symmetric Cryptography
T1573.002 - Asymmetric Cryptography
T1574 - Hijack Execution Flow
T1583
T1583.001 - Domains
T1584.001 - Domains
T1586 - Compromise Accounts
T1587
T1588.001 - Malware