Tracking Crimson Kingsnake
ID: 9df2d49b-c5b2-599f-a65c-7f059d13a21e
STIX ID: report--9df2d49b-c5b2-599f-a65c-7f059d13a21e
Feed Name: KMsec blog
Threat Score
This report documents the Crimson Kingsnake invoice‑fraud campaign: targeted spearphishing lures and follow-up thread hijacks using compromised Office365 accounts and typo‑squatted domains to deliver PDF invoices. The author used VirusTotal pivots to identify victim organizations, recurring metadata fingerprints (PDF author 'hpins'), domain lists, file hashes, and a LiveHunt YARA rule to track the campaign and surface IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
