Coquettte
· Published 21/12/2025 12:41 · Modified 21/12/2025 12:41
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 12:41
- Modified
- 21/12/2025 12:41
- Updated at
- 21/12/2025 12:41
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 23 attack patterns (mitre), 8 malware, 1 countries, 16 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
11 MITREs 7 Malwares 1 APTPublished 04/04/2025 19:54 · Modified 07/04/2025 08:04
-
13 MITREs 6 Malwares 6 Observables 1 APTPublished 03/04/2025 17:18 · Modified 03/04/2025 18:31
Attack patterns (MITRE) (23)
-
T1078 usesValid Accounts
-
T1192 uses
-
T1573.001 usesSymmetric Cryptography
-
T1588.001 usesMalware
-
T1583.001 usesDomains
-
T1027 usesObfuscated Files or Information
-
T1105 usesIngress Tool Transfer
-
T1070.004 usesFile Deletion
-
T1102.002 usesBidirectional Communication
-
T1570 usesLateral Tool Transfer
-
T1566.002 usesSpearphishing Link
-
T1588.002 usesTool
-
T1583.004 usesServer
-
T1071.001 usesWeb Protocols
-
T1204.001 usesMalicious Link
-
T1547.001 usesRegistry Run Keys / Startup Folder
-
T1587.001 usesMalware
-
T1204.002 usesMalicious File
-
T1059.003 usesWindows Command Shell
-
T1102.001 usesDead Drop Resolver
-
T1102 usesWeb Service
-
T1102.003 usesOne-Way Communication
-
T1190 usesExploit Public-Facing Application
Malware (8)
-
Penguish usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:17 · Modified 21/12/2025 13:21
-
Raccoon Stealer V2 usesFamilyPublished 03/04/2025 17:18 · Modified 03/04/2025 17:18
-
Vidar usesFamilyPublished 16/06/2026 09:50 · Modified 16/06/2026 09:50
-
Rescoms usesFamilyPublished 25/05/2025 17:47 · Modified 25/05/2025 17:47
-
Lumma Stealer usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
RecordBreaker usesFamilyPublished 25/05/2025 17:47 · Modified 25/05/2025 17:47
-
Rugmi usesFamilyPublished 04/04/2025 19:54 · Modified 04/04/2025 19:54
-
Amadey - S1025 usesFamilyPublished 29/09/2025 08:06 · Modified 29/09/2025 08:06
Countries (1)
- Russian Federation targets
Indicators (16)
-
1487a4f637a68a5b1dadc379e770431d591421218818164add86c02853a433aaindicates -
coquettte.comindicates -
mercurywork.shopindicates -
https://cia.tf/indicates -
meth.suindicates -
terrorist.ovhindicates -
cybersecureprotect.comindicates -
quitarlosi.cfdindicates -
horrid.xyzindicates -
bad.is-having.funindicates -
xn--xuu.wsindicates -
0983d99e87d9300d4a1b54c08d9a365160e406e4cd681bfd6ef82052d932a5b4indicates -
a07c9275d2628f6dee9271452a66683831d21367a63cdb61ade0fac55f3ed9ffindicates -
https://xn--xuu.ws/indicates -
adbd542caaed33f4d4dd5979676211db7e439341ce3d9cff2622b582a76c7e29indicates -
5558b04220e017f2a69fd88c575ec9450bde361049e42fd67501a0f89ba21834indicates