Nice Try Tonto Team
ID: 676e909c-6b3a-5e76-976d-3a1e5e303361
STIX ID: report--676e909c-6b3a-5e76-976d-3a1e5e303361
Feed Name: Group-IB Blog
Group-IB detected and blocked targeted spear-phishing emails in 2021–2022 that used Royal Road RTF weaponized documents to deploy Bisonal.DoubleT backdoors and a new downloader (TontoTeam.Downloader/QuickMute); the report provides static and dynamic analysis, C2 patterns, file and network IoCs (hashes, IPs, domains), YARA detection rules, and MITRE ATT&CK mappings and attributes the activity with high confidence to the Tonto Team APT, warning of ongoing espionage targeting IT and cybersecurity organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
