Cardinal
· Published 05/02/2026 21:39 · Modified 05/02/2026 21:39
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 05/02/2026 21:39
- Modified
- 05/02/2026 21:39
- Updated at
- 05/02/2026 21:39
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 14 attack patterns (mitre), 2 malware, 6 indicators, 1 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
1 CVE 2 Malwares 6 Observables 1 APTPublished 05/02/2026 20:21 · Modified 05/02/2026 20:40
Attack patterns (MITRE) (14)
-
T1543 usesCreate or Modify System Process
-
T1566 usesPhishing
-
T1082 usesSystem Information Discovery
-
T1070 usesIndicator Removal
-
T1068 usesExploitation for Privilege Escalation
-
T1078 usesValid Accounts
-
T1204 usesUser Execution
-
T1059 usesCommand and Scripting Interpreter
-
T1190 usesExploit Public-Facing Application
-
T1133 usesExternal Remote Services
-
T1055 usesProcess Injection
-
T1562 usesImpair Defenses
-
T1486 usesData Encrypted for Impact
-
T1083 usesFile and Directory Discovery
Malware (2)
-
GotoHTTP usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 29/01/2026 17:47 · Modified 29/01/2026 17:47
-
Black Basta - S1070 usesFamilyPublished 05/02/2026 20:21 · Modified 05/02/2026 20:21
Indicators (6)
-
230b84398e873938bbcc7e4a1a358bde4345385d58eb45c1726cee22028026e9indicates -
bf6686858109d695ccdabce78c873d07fa740f025c45241b0122cecbdd76b54eindicates -
6bd8a0291b268d32422139387864f15924e1db05dbef8cc75a6677f8263fa11dindicates -
5213706ae67a7bf9fa2c0ea5800a4c358b0eaf3fe8481be13422d57a0f192379indicates -
e09686fde44ae5a804d9546105ebf5d2832917df25d6888aefa36a1769fe4eb4indicates -
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261indicates
Vulnerabilities (CVE) (1)
5.7
Medium
NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and …
- Attack vector
- Local
- Published
- 13/01/2026
- Modified
- 05/02/2026