(Heimdal Security) More than 6 months after its creator was sentenced to prison, the infamous {{Citadel}} malware resurges in a modified form, called Atmos. The new strain is currently targeting banks in France and it was also spotted being delivered with Teslacrypt. From {{Zeus}} to Citadel to Atmos – the years may have passed, but cyber criminals are not ready to give up on using the source code it all began with. In fact, this new Citadel variant that researchers have analyzed is modified sufficiently for it to have a new name. That’s why Malwarebytes dubbed it “Atmos” when they first came across it.
TA0043 | TA0042 | TA0001 | TA0002 | TA0003 | TA0004 | TA0005 | TA0006 | TA0007 | TA0008 | TA0009 | TA0011 | TA0010 | TA0040 |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
IP:Port | Timestamp |
---|
Domain | Timestamp |
---|
URL | Timestamp |
---|
Tool: Atmos
Names: Atmos
Description: (Heimdal Security) More than 6 months after its creator was sentenced to prison, the infamous {{Citadel}} malware resurges in a modified form, called Atmos. The new strain is currently targeting banks in France and it was also spotted being delivered with Teslacrypt. From {{Zeus}} to Citadel to Atmos – the years may have passed, but cyber criminals are not ready to give up on using the source code it all began with. In fact, this new Citadel variant that researchers have analyzed is modified sufficiently for it to have a new name. That’s why Malwarebytes dubbed it “Atmos” when they first came across it.
Category: Malware
Type: Banking trojan, Info stealer, Credential stealer
Information: https://heimdalsecurity.com/blog/security-alert-citadel-trojan-resurfaces-atmos-zeus-legacy/
Alienvault-otx: https://otx.alienvault.com/browse/pulses?q=tag:atmos
Last-card-change: 2020-05-24
Source: https://apt.etda.or.th/cgi-bin/listtools.cgi
TA0043 | TA0042 | TA0001 | TA0002 | TA0003 | TA0004 | TA0005 | TA0006 | TA0007 | TA0008 | TA0009 | TA0011 | TA0010 | TA0040 |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
T1053.002 SCHEDULED TASK/JOB : AT at can be used to schedule a task on a system to be executed at a specific date or time. | T1053.002 SCHEDULED TASK/JOB : AT at can be used to schedule a task on a system to be executed at a specific date or time. | T1053.002 SCHEDULED TASK/JOB : AT at can be used to schedule a task on a system to be executed at a specific date or time. |