Update to the REF2924 intrusion set and related campaigns
ID: e5494d8a-17a3-51ac-ab56-3f8c5468d7af
STIX ID: report--e5494d8a-17a3-51ac-ab56-3f8c5468d7af
Feed Name: Elastic Security Labs
Elastic Security Labs analyzes three implants—DOORME (an IIS module backdoor), SIESTAGRAPH (a .NET implant using Microsoft Graph/OneDrive for C2), and a SHADOWPAD loader—linking them to the REF2924 intrusion set and related campaigns attributed to regional/nation-aligned actors (Winnti/ChamelGang). The report includes code-level behavior, obfuscation and persistence techniques, command functionality, observed victim types (including Exchange servers and a foreign ministry), YARA rules, hunting queries, and indicators to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
