logo

VirusTotal += Mandiant Permhash: Unearthing adversary infrastructure and toolkits by leveraging permissions similarity

ID: cb8d3d22-1f16-5c23-b2eb-2b28a6fa0741

STIX ID: report--cb8d3d22-1f16-5c23-b2eb-2b28a6fa0741

Feed Name: VirusTotal Blog

Threat Score
70/100

Date Published: 2023-05-17

Date Updated: 2026-05-01

Author: Emiliano Martinez

...
...

The report analyzes a threat group's distribution infrastructure and modus operandi, using VirusTotal commonalities to identify repeatable patterns (such as .xyz domains and archive.zip filenames), execution parents that drop malicious Chrome extensions, and first-stage artifacts including DMG files and PowerShell scripts; several distribution URLs were observed in the wild and were undetected at the time of writing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.