🇧🇾

Ghostwriter

APT Group 3 zero-day CVEs ETDA ✓

Also Known As 6 names

DEV-0257 PUSHCHA Storm-0257 TA445 UAC-0057 UNC1151

Target Countries 36

Countries highlighted in red

Australia Belarus Canada Switzerland China Colombia Germany Estonia Spain France United Kingdom Ireland India Italy Democratic People's Republic of Korea Republic of Korea Kuwait Kazakhstan Lithuania Latvia Mongolia Malta Mexico Malaysia New Zealand Poland Portugal Romania Serbia Russian Federation Sweden Singapore Thailand Ukraine United States Vietnam

Sectors Targeted

Executive, Legislative, and Other General Government Support 9211 Military Religious, Grantmaking, Civic, Professional, and Similar Organizations 813 Companies power grids) Private Sector Manufacturing Financial Sector Military and Defense Utilities 22 Infrastructure Various Sectors Critical Infrastructure Cryptocurrency Internet Publishing and Broadcasting and Web Search Portals 51913 Trade Defense contractor Energy Critical Infrastructure (transportation Defense contractors Transportation Non-profit Health Care and Social Assistance 62 Public Administration 92 Multiple Grantmaking and Giving Services 8132 Oil and Gas Extraction 211 Technology News Media Oil and Gas Publishing Industries (except Internet) 511 National Security and International Affairs 928110 Retail Couriers and Express Delivery Services 492110 Logistics Computer Systems Design Services 541512 Social Media National Security and International Affairs 928 Media Streaming Distribution Services, Social Networks, and Other Media Networks and Content Providers 5162 Other Information Services 519 Financial Mining, Quarrying, and Oil and Gas Extraction 21 Economic Commodity Contracts Intermediation 523160 Civilian Electronic Healthcare Defence Finance NAICS:44 44 Public Sector Media Space Research and Technology 927 Activism Organizations Telecommunications Business to Business Electronic Markets 42511 Translation and Interpretation Services 54193 Other Services (except Public Administration) 81 Customer Care Telecommunications 517 Information 51 NGOs Defense Finance and Insurance 52 Water Industrial NAICS:31 31 Call Center Pharmaceuticals Research and Development in the Social Sciences and Humanities 54172 Commercial Banking 52211 Computer and Electronic Product Manufacturing 334 Chemical Manufacturing 325 communications Political Entities Journalists Performing Arts Companies 7111 Professional, Scientific, and Technical Services 54 Computer Systems Design and Related Services 54151 All Government Periodical Publishers 51112 NAICS:48 48 Cybersecurity Think tanks Foreign Affairs Banks Arts, Entertainment, and Recreation 71 Educational Services 61 Diplomatic Political Activism Financial Services

Details

Origin 🇧🇾 BY
Last Updated 01 Jun 2022

Malware Families 6

graphsteel
grimplant
huskloader
NJRAT
COBALTSTRIKE
sunseed

MITRE ATT&CK 77

T1002 T1010 T1012 - Query Registry T1016 T1027 - Obfuscated Files or Information T1033 - System Owner/User Discovery T1036 - Masquerading T1041 T1046 T1053.005 - Scheduled Task T1055 - Process Injection T1056 T1057 - Process Discovery T1059 - Command and Scripting Interpreter T1059.001 T1059.003 - Windows Command Shell T1059.005 - Visual Basic T1059.007 - JavaScript T1064 T1071 T1071.001 - Web Protocols T1078 - Valid Accounts T1082 - System Information Discovery T1083 - File and Directory Discovery T1087 T1100 T1102 T1102.002 - Bidirectional Communication T1102.003 - One-Way Communication T1104 T1105 - Ingress Tool Transfer T1113 T1114 - Email Collection T1114.001 - Local Email Collection T1114.002 - Remote Email Collection T1115 T1127 - Trusted Developer Utilities Proxy Execution T1132.001 - Standard Encoding T1137 - Office Application Startup T1140 - Deobfuscate/Decode Files or Information T1176 - Browser Extensions T1189 T1190 - Exploit Public-Facing Application T1193 T1203 T1204 T1204.002 - Malicious File T1205 - Traffic Signaling T1208 T1218 T1218.011 - Rundll32 T1219 T1221 T1471 T1482 T1486 T1497 T1518 - Software Discovery T1518.001 - Security Software Discovery T1539 - Steal Web Session Cookie T1543 T1547 T1547.001 - Registry Run Keys / Startup Folder T1555 T1560 T1564 T1566 - Phishing T1566.001 - Spearphishing Attachment T1573.001 - Symmetric Cryptography T1573.002 - Asymmetric Cryptography T1574 - Hijack Execution Flow T1583 T1583.001 - Domains T1584.001 - Domains T1586 - Compromise Accounts T1587 T1588.001 - Malware