logo

REF2924: how to maintain persistence as an (advanced?) threat

ID: ab3340ca-b8ae-5566-92b8-01bfbc6ad629

STIX ID: report--ab3340ca-b8ae-5566-92b8-01bfbc6ad629

Feed Name: Elastic Security Labs

Threat Score
80/100

Date Published: 2023-03-27

Date Updated: 2026-04-27

...
...

Elastic Security Labs reports on activity attributed to REF2924, describing evolution from custom malware to reuse of open-source tools and public source code. The publication analyzes a .NET Behinder/Godzilla-style webshell, a tiny .NET persistence binary (kavUpdate.exe) that creates and elevates a domain account and exports NTDS backups, and the actor’s use of tools such as AdFind, TFirewall, Impacket/secretsdump, and NTDSDumpEx for credential harvesting and lateral movement; it includes YARA detection, hashes, and recommended detection logic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.