Exploring the REF2731 Intrusion Set
ID: 01699352-e527-5b13-b7d4-44e0114fb862
STIX ID: report--01699352-e527-5b13-b7d4-44e0114fb862
Feed Name: Elastic Security Labs
Elastic Security Labs analyzed REF2731, a multi-stage malspam campaign that uses macro-enabled Word documents to deploy the PARALLAX loader which extracts and executes the NETWIRE RAT; the report details a five-stage chain (macro download → DLL sideload via MsiDb.exe → XORed WAV shellcode with direct syscalls and Heaven's Gate injection into cmd.exe → steganographic PNG containing LZMA-compressed payload → persistence via scheduled task and UAC bypass via CMSTPLUA), provides IOCs (SHA-256 hashes, domains, emails), YARA detection rules, campaign clustering across two campaigns, and an open-source PARALLAX payload extractor to support hunting and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
