Kremlin RATs from Nigeria
ID: 35874d4b-6b22-5f17-85ac-3b1ed8ff8e63
STIX ID: report--35874d4b-6b22-5f17-85ac-3b1ed8ff8e63
Feed Name: Group-IB Blog
Group-IB analysed three phishing campaigns active between 2019 and 2020 that targeted users across Europe and CIS countries by distributing malicious Office documents (malicious macros and exploit-based RTF/XLS) to deliver remote-access Trojans and infostealers (NetWire, AsyncRAT, WSHRAT, NanoCore, AgentTesla). The report maps adversary infrastructure (many DDNS domains, hosting IPs, C2 servers), provides multiple IOCs (SHA1s, domains, email registrants), attributes the activity to a previously unknown Nigerian threat actor, and offers MITRE-mapped defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
