Discovering Splinter: A First Look at a New Post-Exploitation Red Team Tool
ID: 1b11c71f-1b8e-508d-8ce1-0484cb3a088b
STIX ID: report--1b11c71f-1b8e-508d-8ce1-0484cb3a088b
Feed Name: Palo Alto Networks Unit 42
Threat Score
This report details the discovery and technical analysis of Splinter, a Rust-based post-exploitation/red-team tool found on customer systems; it describes the implant's configuration format, capabilities (remote command execution, module injection, file transfer, cloud info gathering, self-delete), C2 URL paths, a sample SHA-256 indicator, and detection/mitigation guidance from Palo Alto Networks, while noting no attribution to a specific threat actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
