Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The hackers use new tools, which have not previously been described: a sophisticated multi-layered loader and a backdoor dubbed SPINNER.
The hackers use new tools, which have not previously been described: a sophisticated multi-layered loader and a backdoor dubbed SPINNER.
As the payload, the Spinner a newly added backdoor is the main component, which is obfuscated by using two methods of obfuscation.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Moreover, there are also phishing emails containing sanctions-related information that has been sent to Russian entities within the Rostec Corporation... several Russian research institutes affiliated with the defense industry received malicious emails.
The DLL executes a portion of the INIT file in charge of cleaning up the files created by the malicious document and creates a scheduled task for persistence
0x10050001 Run command using cmd.exe cmd line Output from Command Line
The payload uses two compiler-level obfuscations: Control flow flattening... Opaque predicates
The loader is a 32-bit DLL utilizing dynamic API resolving with name hashing for evasion and anti-analysis.
The dropper... masquerades as a legitimate Windows executable EFS REKEY Wizard... All the attached documents are crafted to look like official documents from the Russian Ministry of Health
It then decompresses the decrypted buffer... Figure 7: Injection to msiexec.exe
It then collects data about the infected system and creates a string containing... Local IP
It then collects data about the infected system and creates a string containing... Username
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified backdoor used as the main payload in the Twisted Panda espionage campaign; it communicates with a command-and-control server and is used to run additional payloads.
A previously undocumented backdoor used in the Twisted Panda espionage campaign. It establishes persistence, fingerprints infected hosts, communicates with C2 over HTTP/S using RC4-encrypted packets, can self-update, and in older/full variants supports file enumeration, file exfiltration/manipulation, and command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.