Just Another Blue Teamer · @LeeArchinal
82 followers · 135 posts · Server ioc.exchange

everyone! The Check Point Software Technologies Ltd research team continues to discover more tools used by the known as . This time, they shed light on Go-based backdoor dubbed . Check out the article for more details! Enjoy and Happy Hunting!

Link is in the comments!

**I am going to leave one of the MITRE ATT&CK blank. I would like to see if any of you that see this can help FILL in that blank! If so, leave your thoughts in the comments OR send me a DM!**

Notable TTPs:
TA0005 - Defense Evasion
T1574.002 - Hijack Execution Flow: DLL Side-Loading

TA0002 - Execution
T1059.003 - Command And Scripting Interpreter: Windows Command Shell
T1059.001 - Command And Scripting Interpreter: PowerShell

TA0003 - Persistence
T[Let me know what persistence techniques you see!]

TA0007 - Discovery
T1033 - System Owner/User Discovery
T1015 - System Network Configuration Discovery

#happyfriday #apt #camarodragon #tinynote #cybersecurity #itsecurity #infosec #blueteam #threatintel #threathunting #ThreatDetection #happyhunting

Last updated 1 year ago