logo

Update to the REF2924 intrusion set and related campaigns

ID: e5494d8a-17a3-51ac-ab56-3f8c5468d7af

STIX ID: report--e5494d8a-17a3-51ac-ab56-3f8c5468d7af

Feed Name: Elastic Security Labs

Threat Score
85/100

Date Published: 2023-02-07

Date Updated: 2026-04-27

...
...

Elastic Security Labs analyzes three implants—DOORME (an IIS module backdoor), SIESTAGRAPH (a .NET implant using Microsoft Graph/OneDrive for C2), and a SHADOWPAD loader—linking them to the REF2924 intrusion set and related campaigns attributed to regional/nation-aligned actors (Winnti/ChamelGang). The report includes code-level behavior, obfuscation and persistence techniques, command functionality, observed victim types (including Exchange servers and a foreign ministry), YARA rules, hunting queries, and indicators to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.