🇺🇸
KNOCKOUT SPIDER
APT Group
Information theft and espionage
1 zero-day CVE
ETDA ✓
Also Known As 4 names
DeathStalker
EvilNum
Jointworm
TA4563
Target Countries 11
Countries highlighted in red
Albania
Australia
Belgium
Canada
Cyprus
France
Ireland
Israel
Italy
Ukraine
United States
Details
Origin
🇺🇸 US
Last Updated
01 Jun 2022
Malware Families 45
wannacryptor
hermeticwiper
REVENGERRAT
hupigon
huskloader
expiro
redcap
havex_rat
dofloo
graftor
pykspa
TINY
NJRAT
limerat
win.qhost
kuaibu8
feodo
troublegrabber
CRYXOS
virut
backnet
webmonitor
sarhust
agent_tesla
EMOTET
agent_btz
Asprox
mikey
AZORULT
zgrat
outcrypt
zhmimikatz
WACATAC
blacknix_rat
SMOKELOADER
TRICKBOT
blacknet_rat
ave_maria
mokes
teambot
kuluoz
wannaren
lokipws
agendacrypt
revenge_rat
MITRE ATT&CK 132
T1001 - Data Obfuscation
T1003
T1003.003
T1003.006
T1006
T1016
T1018 - Remote System Discovery
T1021
T1021.001
T1021.004
T1021.007
T1027 - Obfuscated Files or Information
T1041
T1046
T1047
T1055 - Process Injection
T1056 - Input Capture
T1059 - Command and Scripting Interpreter
T1059.001 - PowerShell
T1059.003 - Windows Command Shell
T1059.004
T1059.007 - JavaScript
T1068 - Exploitation for Privilege Escalation
T1069
T1069.002
T1069.003
T1070
T1070.001 - Clear Windows Event Logs
T1070.004
T1070.008
T1071.001 - Web Protocols
T1071.004 - DNS
T1074
T1078
T1078.004
T1082
T1083
T1087
T1087.002
T1087.003
T1087.004
T1090 - Proxy
T1098
T1098.001
T1098.003
T1098.005
T1102
T1105 - Ingress Tool Transfer
T1114 - Email Collection
T1114.003
T1133
T1136
T1140 - Deobfuscate/Decode Files or Information
T1176 - Browser Extensions
T1190 - Exploit Public-Facing Application
T1204
T1204.001
T1210 - Exploitation of Remote Services
T1211 - Exploitation for Defense Evasion
T1213
T1213.002
T1213.003
T1213.005
T1217
T1219
T1219.002
T1222.001 - Windows File and Directory Permissions Modification
T1412 - Capture SMS Messages
T1449 - Exploit SS7 to Redirect Phone Calls/SMS
T1450 - Exploit SS7 to Track Device Location
T1454 - Malicious SMS Message
T1484
T1484.002
T1486 - Data Encrypted for Impact
T1490 - Inhibit System Recovery
T1496 - Resource Hijacking
T1497 - Virtualization/Sandbox Evasion
T1497.001
T1498 - Network Denial of Service
T1529 - System Shutdown/Reboot
T1530
T1538
T1539
T1543
T1543.002
T1547.001 - Registry Run Keys / Startup Folder
T1548
T1548.002
T1552
T1552.001
T1552.004
T1553
T1553.002
T1555
T1555.005
T1556
T1556.006
T1556.009
T1562
T1562.001
T1564
T1564.008
T1566 - Phishing
T1566.001
T1566.002
T1566.004
T1567
T1567.002
T1572
T1574
T1574.001
T1578
T1578.002
T1580
T1583
T1583.001
T1585
T1585.001
T1588
T1588.001
T1588.002
T1589
T1589.001
T1598
T1598.001
T1598.003
T1598.004
T1621
T1656
T1657
TA0011 - Command and Control
TA0029 - Privilege Escalation