🇺🇸

KNOCKOUT SPIDER

APT Group Information theft and espionage 1 zero-day CVE ETDA ✓

Also Known As 4 names

DeathStalker EvilNum Jointworm TA4563

Target Countries 11

Countries highlighted in red

Albania Australia Belgium Canada Cyprus France Ireland Israel Italy Ukraine United States

Details

Origin 🇺🇸 US
Last Updated 01 Jun 2022

Malware Families 45

wannacryptor
hermeticwiper
REVENGERRAT
hupigon
huskloader
expiro
redcap
havex_rat
dofloo
graftor
pykspa
TINY
NJRAT
limerat
win.qhost
kuaibu8
feodo
troublegrabber
CRYXOS
virut
backnet
webmonitor
sarhust
agent_tesla
EMOTET
agent_btz
Asprox
mikey
AZORULT
zgrat
outcrypt
zhmimikatz
WACATAC
blacknix_rat
SMOKELOADER
TRICKBOT
blacknet_rat
ave_maria
mokes
teambot
kuluoz
wannaren
lokipws
agendacrypt
revenge_rat

MITRE ATT&CK 132

T1001 - Data Obfuscation T1003 T1003.003 T1003.006 T1006 T1016 T1018 - Remote System Discovery T1021 T1021.001 T1021.004 T1021.007 T1027 - Obfuscated Files or Information T1041 T1046 T1047 T1055 - Process Injection T1056 - Input Capture T1059 - Command and Scripting Interpreter T1059.001 - PowerShell T1059.003 - Windows Command Shell T1059.004 T1059.007 - JavaScript T1068 - Exploitation for Privilege Escalation T1069 T1069.002 T1069.003 T1070 T1070.001 - Clear Windows Event Logs T1070.004 T1070.008 T1071.001 - Web Protocols T1071.004 - DNS T1074 T1078 T1078.004 T1082 T1083 T1087 T1087.002 T1087.003 T1087.004 T1090 - Proxy T1098 T1098.001 T1098.003 T1098.005 T1102 T1105 - Ingress Tool Transfer T1114 - Email Collection T1114.003 T1133 T1136 T1140 - Deobfuscate/Decode Files or Information T1176 - Browser Extensions T1190 - Exploit Public-Facing Application T1204 T1204.001 T1210 - Exploitation of Remote Services T1211 - Exploitation for Defense Evasion T1213 T1213.002 T1213.003 T1213.005 T1217 T1219 T1219.002 T1222.001 - Windows File and Directory Permissions Modification T1412 - Capture SMS Messages T1449 - Exploit SS7 to Redirect Phone Calls/SMS T1450 - Exploit SS7 to Track Device Location T1454 - Malicious SMS Message T1484 T1484.002 T1486 - Data Encrypted for Impact T1490 - Inhibit System Recovery T1496 - Resource Hijacking T1497 - Virtualization/Sandbox Evasion T1497.001 T1498 - Network Denial of Service T1529 - System Shutdown/Reboot T1530 T1538 T1539 T1543 T1543.002 T1547.001 - Registry Run Keys / Startup Folder T1548 T1548.002 T1552 T1552.001 T1552.004 T1553 T1553.002 T1555 T1555.005 T1556 T1556.006 T1556.009 T1562 T1562.001 T1564 T1564.008 T1566 - Phishing T1566.001 T1566.002 T1566.004 T1567 T1567.002 T1572 T1574 T1574.001 T1578 T1578.002 T1580 T1583 T1583.001 T1585 T1585.001 T1588 T1588.001 T1588.002 T1589 T1589.001 T1598 T1598.001 T1598.003 T1598.004 T1621 T1656 T1657 TA0011 - Command and Control TA0029 - Privilege Escalation

Related Zero-Days 1