(ThreatConnect) This threat has been identified using a malware implant specifically known as “Spindest” or “Backdoor.Apocalipto”. This threat appears to have been in use for some time, and has been primarily observed being delivered from URLs on compromised intermediary websites along with other possibly initial infection vectors such as spearphishing operations. The implant generally uses dynamic command and control (C2) infrastructure.
TA0043 | TA0042 | TA0001 | TA0002 | TA0003 | TA0004 | TA0005 | TA0006 | TA0007 | TA0008 | TA0009 | TA0011 | TA0010 | TA0040 |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
IP:Port | Timestamp |
---|
Domain | Timestamp |
---|
URL | Timestamp |
---|
Tool: Spindest
Names: Spindest, Backdoor.Apocalipto
Description: (ThreatConnect) This threat has been identified using a malware implant specifically known as “Spindest” or “Backdoor.Apocalipto”. This threat appears to have been in use for some time, and has been primarily observed being delivered from URLs on compromised intermediary websites along with other possibly initial infection vectors such as spearphishing operations. The implant generally uses dynamic command and control (C2) infrastructure.
Category: Malware
Type: Backdoor
Information: https://threatconnect.com/blog/threatconnect-enables-healthy-networking-biomed-life-sciences-industry/
Last-card-change: 2020-04-20
Source: https://apt.etda.or.th/cgi-bin/listtools.cgi
TA0043 | TA0042 | TA0001 | TA0002 | TA0003 | TA0004 | TA0005 | TA0006 | TA0007 | TA0008 | TA0009 | TA0011 | TA0010 | TA0040 |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |