SideWinder APT: Futuristic Tactics & Techniques
ID: 5c8ec97c-d4c6-56cb-b1ba-f4705bae5d46
STIX ID: report--5c8ec97c-d4c6-56cb-b1ba-f4705bae5d46
Feed Name: Cyble Blog
Cyble Research documents a SideWinder APT campaign delivering malware through a CVE-2017-11882-exploiting Word document (Protocol.doc) and LNK files inside an archive (Audit_Observation2019.zip). The deployed components (Rekeywiz.exe and Duser.dll) enable EFS, perform ECDH-P256-based file encryption, create the mutex "Local\ba76e584-735b-45d5-ab75-7ecb8ec8f208", and communicate with C2 185.99.133.58; the report includes file MD5s, domains/IPs, and recommended mitigations such as disabling EFS and patching systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
