Gage
@circuitous__
Threat Analyst
ID: 1032259826120884225
22-08-2018 13:34:55
237 Tweet
831 Followers
265 Following
Looks like more potential #LazarusGroup? More #Azure and remote template but the domain 404s Z Venture Capital Presentation(Protected).docx 98e30453bbf1c9c9f48368f9bbe69edd word.azureword[.]com 104.168.162.167 @t0001100000 Jazi ςεяβεяμs - мαℓωαяε яεsεαяςнεя Shadow Chaser Group
#spymax #Android RAT with interesting #Pakistan-themed name. Anyone else have anything on this? /apks/Constitution_of_Pakistan_1973_v1.2.apk 6b7aaaacd33b8da0c8cb4a43d60259a0 37.221.115.62 💥 𝕭𝖑4𝖈𝖐𝖍0𝖑3𝖟 👾 MalwareHunterTeam ςεяβεяμs - мαℓωαяε яεsεαяςнεя @t0001100000
Gage 💥 𝕭𝖑4𝖈𝖐𝖍0𝖑3𝖟 👾 MalwareHunterTeam ςεяβεяμs - мαℓωαяε яεsεαяςнεя @t0001100000 ᴘᴀʀᴛʜɪ Tommy M (TheAnalyst) JAMESWT_MHT Arkbird Yury Polozov It appears to be recently discovered Snow Leopard group that monitors Pakistani users via SpyMax and AndroSpy RATs Based on the C&C, there have been more APKs with Pakistan name uploaded on VT this year Source of distribution is still 3rd party app store xinbs.net/a/xwdt/xydt/96…
More potential #evlinum or just crimeware? Basic template and remote domain. It's similar to IOCs in DBAPPSecurity's report: ti.dbappsecurity.com.cn/blog/articles/… Documents.docx e726520b3ad875b516df6c3d25476444 http://wazalpne[.]com/ xml 54bcaa83d71232b1b4fa4aa47a41b3fa @t0001100000 Jazi
I am beyond excited to drop new research today with my coauthor The Banshee Queen👑 on TA423/RedLadon (aka Leviathan). It’s rare for Threat Insight to partner with others but Sveva and PwC Global Threat Intelligence Team are among the rarest talents. 1/3🧵 proofpoint.com/us/blog/threat…